Firehydrant

Security checks across malware telemetry and agentic risk

Overview

This FireHydrant skill is coherent, but it gives an agent broad authenticated power to change or delete incident-management data through a raw API proxy without clear confirmation guidance.

Install only if you are comfortable letting the agent operate against FireHydrant through Membrane. Use a least-privileged FireHydrant account, prefer predefined Membrane actions, pin the CLI version where possible, and require explicit confirmation before any request that creates, updates, or deletes incident data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill documents a generic proxy request mechanism that supports all HTTP methods, including POST, PUT, PATCH, and DELETE, but does not warn that these can modify or delete production incident-management data. In an agent setting, presenting raw request capability without confirmation or guardrails increases the risk of unintended destructive actions against FireHydrant resources.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal