Home Fix-It

Security checks across malware telemetry and agentic risk

Overview

Home Fix-It is a coherent home-repair assistant that stores maintenance data locally, with some consent and safety-caution improvements users should be aware of.

Before installing, expect the skill to create and update local home-maintenance files in your workspace and to store household details locally. Ask the agent to confirm target paths before writes, and do not rely on it for gas, major electrical, structural, mold, asbestos, or HVAC/furnace work without a licensed professional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Confidence
88% confidence
Finding
The maintenance template includes potentially hazardous appliance/service tasks such as flushing a water heater and servicing a furnace/heating system without any safety cautions, limits, or advice to use a qualified professional beyond a brief note on servicing. Users may attempt tasks involving hot water, gas, combustion systems, pressure, or electrical components without understanding the risks, which can lead to injury or property damage.

Missing User Warnings

Medium
Confidence
78% confidence
Finding
The example normalizes writing to a user path without any confirmation, preview, or warning, which can train users to accept silent persistence of generated content. In an agent setting, this pattern is risky because it can lead to unintended modification of user files, overwriting notes, or creating misleading records without explicit consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal