CallerAPI

Security checks across malware telemetry and agentic risk

Overview

This is a coherent CallerAPI connector skill, but users should treat phone-number lookups as potentially sensitive personal-data queries.

Install only if you intend to use CallerAPI through an OOMOL-connected account. Use phone-number and HLR/carrier lookups only for authorized, lawful purposes, avoid unnecessary enrichment, and be mindful that results may expose personal or business-related information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill explicitly enables lookup of spam reputation, business details, complaints, and optional HLR/carrier data for a phone number, but provides no privacy warning, usage constraints, or notice about handling personal data. This increases the risk that users or downstream agents will query personal phone numbers without considering consent, legal restrictions, or data-minimization obligations.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal