Back to skill

Security audit

free-weath组合包

Security checks across malware telemetry and agentic risk

Overview

This bundle is not clearly malicious, but it combines broad read/write/execute authority with health-data handling and vague scoping, so users should review it carefully before installing.

Install only if you are comfortable granting a broad bundle read/write/execute access and potentially sharing health data or API credentials. Prefer separate, narrowly scoped skills unless the publisher provides clearer privacy, command, file, and consent boundaries.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The bundle advertises a lifestyle/weather use case but declares powerful read/exec/write capabilities at the top level, which materially expand what the skill can do beyond the stated purpose. In a bundled skill that also references health-data sync, these permissions increase the risk of arbitrary command execution, local file modification, and misuse of sensitive data if any member workflow is abused or implemented unsafely.

Description-Behavior Mismatch

Medium
Confidence
81% confidence
Finding
The manifest presents the package as a generic marketing bundle, while the body claims concrete operational behaviors such as weather retrieval, game building, and health-data synchronization. This mismatch can mislead users and reviewers about the real functionality and data flows, reducing informed consent and obscuring higher-risk behaviors in constituent skills.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The bundle discusses health-data synchronization alongside exec/write capabilities but does not clearly disclose that sensitive personal health information may be accessed, transmitted, or modified. Because health data is highly sensitive, inadequate disclosure and safeguards raise the risk of privacy violations, unintended exfiltration, and unsafe data handling.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.