Back to skill

Security audit

android-control

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent Android automation guide, but it enables sensitive device, app, screenshot, and message control without enough scoping or consent safeguards.

Install only if you intend to let the agent operate Android devices and connected app accounts you control. Treat screenshots, UI dumps, message reads, message sends, marketplace posting, and multi-account automation as sensitive actions that should require explicit user approval and clear device/account scope.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill advertises very broad trigger terms such as Android device operation, WeChat automation, screen understanding, UI automation, and multi-device management, which can cause the skill to activate in many contexts beyond a user's clear intent. Because the skill enables remote device control and message operations, ambiguous activation materially increases the chance of unintended sensitive actions on real devices.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill provides capabilities for remote control of Android devices, screenshot capture, UI hierarchy extraction, app management, and reading/sending messages, including WeChat-specific operations, but it does not warn about privacy, consent, account, or device integrity risks. In this context, omission of warnings and safeguards is dangerous because users or downstream agents may treat the automation as routine and use it to access private communications, control accounts, or perform unauthorized actions on multiple devices.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.