Fire Skills

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed fire-safety guidance skill with no executable code, though users should be aware it asks the agent to localize advice and may keep reminder-style safety state.

Before installing, consider sharing only the country, state, or region needed for fire rules and emergency numbers. Review any reminder or saved checklist behavior if your agent persists skill state, especially details about your home safety setup.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to detect the user's location in order to localize emergency numbers, fire regulations, and guidance, but it does not require user notice, consent, or a privacy-preserving fallback. Inferring or collecting location without transparency can expose sensitive personal context and may cause the agent to process more data than necessary, especially in emergency scenarios where users may not realize location is being derived.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal