Monday

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Monday.com connector skill that can make real account changes, so it should be used carefully but does not show malicious behavior.

Install only if you trust OOMOL and intend to let the agent operate your Monday account through the oo CLI. Before any create, update, archive, delete, move, membership, department, form, doc, dashboard, or board-changing action, confirm the exact target and payload; read-only listing actions are lower risk but may still expose private business data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation text is excessively broad: 'Use this skill for ANY Monday request' and 'Whenever a task involves Monday' can cause the agent to select this skill for loosely related prompts without first validating user intent or least-privilege alternatives. In this skill, that matters because the exposed actions include destructive operations such as delete, archive, move, and update, so over-triggering increases the chance of unintended state-changing use against a connected Monday account.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill documents a destructive state-changing action ('Archive a Monday item') but provides no warning, confirmation guidance, or note about reversibility. In an agentic context, this increases the chance of unintended archival of user data, especially because the skill is positioned for broad Monday usage and encourages direct execution once the schema is fetched.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal