Weather Pulse

Security checks across malware telemetry and agentic risk

Overview

Weather Pulse is a disclosed weather and air-quality lookup skill that only makes user-requested API calls to weather providers using user-supplied credentials.

Install only if you are comfortable providing QWeather and/or WAQI credentials and sending queried city names, coordinates, or WAQI 'here' lookups to those providers. Use environment variables or a private secret store, and copy QWEATHER_API_HOST only from the QWeather console.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger list is very broad and includes many common terms such as 'weather', 'temperature', 'humidity', 'wind', and generic Chinese equivalents that are likely to appear in ordinary conversation. This can cause the skill to activate unintentionally, leading to tool over-invocation, unnecessary external API calls, quota exhaustion, and possible unintended sharing of user location or queried places with third-party weather providers.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal