AddressZen

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a disclosed AddressZen automation helper, with some ordinary but worth-checking installation and trigger-scope caveats.

Install this if you want AddressZen-related automation. Before running the oo CLI curl-to-bash command, inspect the installer or use a trusted package/source if available, and be aware the skill may activate on broadly AddressZen-related requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
97% confidence
Finding
This markdown file defines invocation guidance, so vague-trigger review applies. The phrasing "ANY AddressZen request" and "Whenever a task involves AddressZen" is extremely broad and does not clarify boundaries, exclusions, or example/non-example cases, which could cause unintended invocation for loosely related mentions of AddressZen.

External Script Fetching

High
Category
Supply Chain
Content
- **`oo: command not found`** — install the oo CLI (other platforms: <https://cli.oomol.com/install-guide.md>):

  ```bash
  curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
  ```

  ```powershell
Confidence
90% confidence
Finding
curl -fsSL https://cli.oomol.com/install.sh | bash

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal