Then it is detectable. Those permissions should have a third option alongside allow and block - spoof.