omadeus

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill does not contain executable code, but its advertised Omadeus purpose is unclear because it sends users to a different API domain and mentions unrelated Trello credentials.

Install only after the publisher clarifies why Omadeus calls target milestone.xeba.ir, removes or explains the Trello credential warning, documents the exact credentials and scopes required, and labels which API operations can change live data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs users to perform direct REST API operations with curl against a remote service without clearly warning that these actions may modify live data, transmit credentials, or affect production entities. In an agent skill context, this increases the chance of unsafe use, accidental state changes, and inappropriate handling of secrets, especially since the notes imply privileged API access.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal