DataForSEO

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed DataForSEO connector wrapper for read-oriented SEO and account lookup actions, with no hidden scripts or malicious behavior found.

Install only if you intend to use OOMOL with a connected DataForSEO account. The skill can query account usage and run DataForSEO live data requests that may consume service credits, so review requested payloads for cost and scope before allowing large or repeated queries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The skill metadata and description claim the skill is for 'searching and reading data,' but the body explicitly allows broader action classes and includes generic safety guidance for create/update/post/delete operations. This mismatch can mislead routing, approval, or trust decisions, causing an agent or reviewer to treat the skill as read-only when its workflow is written to accommodate state-changing operations.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger text says to use this skill for 'ANY DataForSEO request' and 'Whenever a task involves DataForSEO,' which is overly broad and can cause the skill to be invoked for vague mentions or tangential references. Overbroad invocation increases the chance of unintended command execution, unnecessary credentialed access, or bypass of safer, narrower workflows.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal