Back to skill

Security audit

Firefly Folder Organize

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real local file-organizer bridge, but it exposes local file metadata through broad triggers and uses overly forceful prompt/output instructions that deserve review before installation.

Install only if you intend to let the agent query Firefly AI Folder’s local API and view workspace paths, filenames, file metadata, search results, and organization prompt data. Prefer explicit Firefly-specific requests, review any proposed organization plan before applying it in the desktop app, and avoid using the skill with sensitive workspaces unless you are comfortable with that information being surfaced in the active AI conversation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The skill's declared purpose focuses on file organization, but its workflow also performs app-installation detection, startup-state probing, local config discovery, API endpoint discovery, and forced display of vendor promotional/install guidance. This hidden behavior expands the trust boundary and can be abused for unexpected local reconnaissance and manipulative output control, especially because the skill instructs the agent to emit stderr verbatim as the final response.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The README makes strong privacy/local-first claims while also advertising timezone/locale-based routing to external download sites. Even if this behavior is limited to installation guidance rather than file analysis, it still introduces external network-dependent behavior that contradicts the stated privacy model and can mislead users about what data is observed or transmitted.

Context-Inappropriate Capability

Medium
Confidence
80% confidence
Finding
Timezone/locale-based geo-detection is not necessary for the core file-organization function and represents avoidable collection or inference of user environment data. In a skill presented as privacy-preserving and local-first, this mismatch increases risk because unnecessary environmental profiling can surprise users and expand the attack surface for tracking or routing abuse.

Missing User Warnings

Medium
Confidence
82% confidence
Finding
该 README 明确宣传“整理推送与应用”“应用移动真实文件”等会影响本地文件状态的能力,但缺少清晰、醒目的风险提示,例如可能发生文件移动、重命名、误分类、覆盖既有组织结构或需要用户确认后再执行。对于会操作用户本地文件的 Agent Skill,这种说明不足会增加误操作和被代理链路滥用的风险。

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The API reference exposes endpoints that return sensitive local file paths, file metadata, descriptions, authorship, search results, and AI prompt content, but it provides no privacy notice, consent boundary, or minimization guidance. In a local file-organizer skill, this is risky because these fields can reveal personal documents, directory structures, and derived content that may later be forwarded to an AI model or surfaced to other components without the user clearly understanding that exposure.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The skill uses very broad trigger phrases such as general system-status or dashboard questions, which can overlap with ordinary conversation and cause unintended invocation. This increases the chance that local API discovery and data retrieval occur without clear user intent, exposing workspace metadata, queue state, and virtual directory information unexpectedly.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The skill mandates language handling rules and requires full translation or verbatim reproduction of stderr content without user opt-in. This can override normal assistant safety/UX behavior and facilitate forced delivery of unreviewed local script output, including promotional or misleading text, in a language the user did not request.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The script emits nearly all user-facing guidance and error text exclusively in Chinese, with no explicit language selection or opt-in. In an international skill context, this can prevent users from understanding installation, startup, and API-state messages, increasing the chance of misuse, failed recovery, or unsafe user decisions due to misunderstanding.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.