Weather Daily

Security checks across malware telemetry and agentic risk

Overview

This is a coherent weather reminder skill that discloses its optional saved preferences and recurring notification behavior.

Before installing, know that enabling pushes stores your user ID, city, unit, timing, and channel preferences locally and creates recurring notification jobs. Use the status and off commands to review or disable them, and do not treat the skill as an official emergency alert source.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger phrases are broad, generic weather expressions that closely match ordinary user speech, making accidental invocation more likely. In this skill's context, unintended activation is more concerning because the skill supports registration and push/subscription workflows, so a casual weather query could route into a stateful skill with persistence and notification side effects.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal