Ffcli

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Fireflies.ai meeting lookup helper, with real but proportionate risks from a third-party CLI, API key use, and sensitive meeting content.

Install only if you trust the @ruigomeseu ffcli package and are authorized to let an agent access Fireflies meeting metadata, transcripts, summaries, and action items. Prefer a limited or dedicated API key if available, avoid broad or accidental meeting queries, and rotate the key if local config or OpenClaw settings may have been exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger list includes broad phrases such as "transcript," "what was discussed," and "meeting summary," which are common in normal conversation and may cause the skill to activate when the user did not specifically intend to query Fireflies.ai. Because this skill accesses meeting transcripts and summaries, accidental invocation can expose sensitive meeting data or route user requests to an external third-party tool unnecessarily.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal