Gemini Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Gemini website automation helper, but users should understand it sends prompts through their logged-in Gemini web session.

Install this only if you are comfortable having the agent use your OpenClaw browser’s signed-in Gemini account. Avoid sending secrets or sensitive personal, business, or account data unless you are willing to share it with Gemini, and be aware that generated images may temporarily exist as local downloads before being returned.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The image-generation trigger list includes very broad everyday terms such as “画” and “海报”, which can match many normal requests unrelated to image generation. In this skill, that can cause unintended invocation of a browser-based workflow that sends user content to gemini.google.com and may perform authenticated actions without sufficiently clear user intent.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill description does not disclose that prompts are transmitted to gemini.google.com and depend on an authenticated Google session. This creates a privacy and consent risk because users may unknowingly send sensitive data to a third-party web service through a logged-in browser context.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal