中国天气预报查询 (China Weather)

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a straightforward China weather lookup tool that runs a bundled Python script and contacts weather.com.cn for forecast data.

Install this if you want China-focused weather forecasts from weather.com.cn. Expect it to run python3 locally and send queried city names to weather.com.cn; use it for Chinese city weather requests and do not approve unrelated shell commands under this skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
77% confidence
Finding
The trigger phrases are very broad, everyday weather questions with no clear invocation boundaries, which increases the chance the agent auto-selects this skill in many casual conversations. Because the skill performs network-backed execution, over-broad triggering can lead to unnecessary external requests or unintended tool use without strong user intent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal