Nimble

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This instruction-only Nimble scooter skill is purpose-aligned, but users should be aware it describes Bluetooth device access and commands that could change or reset scooter settings.

Before installing or using it, confirm you are comfortable with an assistant helping access a scooter over Bluetooth and potentially changing or resetting scooter settings. Treat reset, speed-limit, firmware, and export-related actions as sensitive and perform them only with clear confirmation.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If used, these commands could change how the scooter behaves or erase its current configuration.

Why it was flagged

The skill openly documents commands that can change scooter settings and restore factory settings. This is aligned with the stated scooter configuration and troubleshooting purpose, but these are high-impact physical-device actions.

Skill content
参数配置 | 修改速度限制、灯效等设置 ... `Nimble 重置` - 恢复出厂设置
Recommendation

Only run configuration or reset actions when the user explicitly requests them, the scooter is in a safe state, and the user understands the effect.

What this means

The skill may access scooter status and riding information if paired with a real device-capable runtime.

Why it was flagged

The skill describes connecting to a local scooter over Bluetooth and reading device and riding information. This is expected for the integration, but it represents access to a user's physical device and mobility-related data.

Skill content
设备连接 | 通过蓝牙连接 Nimble 设备 ... 读取设备状态、电池信息、行驶数据
Recommendation

Use it only with scooters you own or are authorized to manage, and avoid sharing exported riding statistics unless intended.