Nova Accountability
PassAudited by VirusTotal on Apr 22, 2026.
Findings (1)
The skill contains shell injection vulnerabilities in `scripts/monday-api.sh` due to unsafe handling of arguments in the `query` function and `update` command. Additionally, the `SKILL.md` instructions contain high-risk directives for an autonomous agent, such as 'Don't limit yourself' when messaging people and spawning sub-agents, which could lead to unauthorized communications or resource exhaustion. While the behavior aligns with the stated purpose of a proactive 'Accountability' manager, the combination of insecure scripting and broad operational autonomy warrants a suspicious classification.
