Back to skill

Security audit

Household Airflow Comfort Map

Security checks across malware telemetry and agentic risk

Overview

This is a document-only home comfort skill, but its examples undermine its own safety limits by steering the agent into HVAC, window-safety, product, and health-adjacent advice.

Review before installing. The package does not appear to contain malware or code-execution risk, but its prompt examples may cause an assistant to give overconfident home ventilation, HVAC, product, or health-adjacent recommendations. It should be revised so examples stay limited to observation-based comfort routines and consistently defer equipment, symptoms, hazardous air, and safety concerns to qualified guidance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The README example expands a comfort-mapping skill into HVAC-style diagnosis and equipment advice by attributing room temperature issues to duct distance/obstruction and recommending booster fans. That conflicts with the stated safety boundary and can cause the agent to give users overconfident building-system guidance outside its intended scope.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The README includes specific window-ventilation instructions such as leaving windows open while AC runs and prescribing opening widths, despite the manifest saying it avoids unsafe window use. This is dangerous because it normalizes potentially unsafe ventilation behavior without accounting for outdoor air quality, security, weather, building rules, or appliance-specific hazards.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The example moves beyond comfort planning into health and air-quality guidance by discussing weakness, dizziness, stale air, fresh-air systems, and reducing CO2 concentration. In this context, that can mislead users into relying on non-medical, non-validated advice for symptoms that may indicate a health or indoor-environment hazard.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The usage scenarios materially expand the skill from observational comfort planning into HVAC diagnosis, product recommendations, and energy-bill analysis. This is dangerous because downstream agents may follow the concrete examples over the stated safety boundary, causing the skill to produce advice outside its intended competence and potentially unsafe or misleading recommendations.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The expected outputs directly contradict the documented safety boundary by prescribing prohibited actions, including HVAC causal analysis, device recommendations, specific fan-placement strategies, and air-quality claims. These examples are especially risky because examples in prompt skills often act as strong behavioral instructions, overriding earlier constraints and leading the model to generate unsafe, unauthorized, or medically adjacent guidance.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
Scenario 4 hardcodes a Chinese-language, China-specific response pattern without any stated locale gating or user preference requirement. While not directly a safety exploit, it can cause inappropriate region-specific advice, assumptions about products and housing norms, and inconsistent behavior that bypasses the skill's general safety framing.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.