Chatwork

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Chatwork connector that can read and change Chatwork data through OOMOL, with confirmation instructions for writes and deletes.

Install this only if you trust OOMOL's connector path with your Chatwork account. Review requested actions before approval, especially posting, updating, creating tasks, or deleting messages, because those change shared Chatwork data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The instruction to use this skill for "ANY Chatwork request" is overly broad and can cause the agent to invoke the skill whenever Chatwork is merely mentioned, rather than when the user actually intends an external action. In an agent setting, ambiguous routing increases the chance of unintended data access or state-changing operations being selected without sufficient narrowing of user intent.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal