Loyverse

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed read-only Loyverse connector skill, with sensitive account access that matches its stated purpose.

Install only if you want your agent to read data from your connected Loyverse account through OOMOL. Be aware it can access customer, receipt, item, store, category, and merchant profile data; review connector responses before sharing sensitive outputs externally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill metadata says to use this skill for ANY Loyverse request and instead of calling the API directly, which can cause overly broad automatic invocation even when a narrower or safer path would be more appropriate. In an agentic environment, this increases the chance of unintended connector use and unnecessary access to account data, especially because the skill is framed as the default path for all Loyverse-related tasks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal