Back to skill

Security audit

Gemini Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Gemini web automation helper, but users should understand that their prompts and generated images go through Gemini and may use a logged-in browser profile.

Install only if you are comfortable having selected prompts sent to Gemini through the OpenClaw browser profile. Avoid sending secrets or sensitive personal data, and clean up downloaded generated images if they should not remain on disk.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The image-generation trigger list includes the standalone word "画", which is a very common everyday term in Chinese and can appear in requests unrelated to image generation. This can cause the skill to activate unexpectedly and send user content to Gemini without clear intent, creating privacy and unintended external-action risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow instructs the agent to send user prompts directly to gemini.google.com and depend on an authenticated session, but it does not require a user-facing disclosure or confirmation before transmitting potentially sensitive content. This is dangerous because users may not realize their data is being shared with a third-party service under the operator's logged-in account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The flow explicitly instructs the agent to download generated images to local storage and then send them back through another channel, but it provides no guidance on user consent, retention limits, deletion, or handling of potentially sensitive generated content. This creates a real data-handling risk because local downloads can persist on disk, leak across sessions, or expose private/generated material beyond the minimum needed to complete the task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language instructions and suggested user messages are all presented in Chinese, which may effectively force a specific language or locale for the interaction. There is no stated option for the user to choose another language or confirmation that the skill is intentionally limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The selector set explicitly targets Chinese strings like "发送" and "图片" alongside English strings, which embeds language assumptions into the skill behavior. There is no natural-language indication that the skill is limited to specific locales or that users can choose supported languages, which can violate locale-choice policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.