Refiner

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Refiner connector wrapper that uses the OOMOL oo CLI and includes user-confirmation guidance for state-changing actions.

Install this only if you intend to let your agent operate your connected Refiner workspace through OOMOL. Review the oo CLI install step before running it, and require explicit confirmation for contact updates, event tracking, response tagging, and segment membership changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The instruction to use this skill for ANY Refiner request creates an over-broad routing rule that can cause an agent to invoke the skill automatically whenever Refiner is mentioned, without first validating user intent, least-privilege needs, or whether a safer read-only path exists. In this skill, that risk is amplified because the same skill exposes both read and state-changing actions, so ambiguous requests could be escalated into unintended modifications if downstream confirmation logic fails or is bypassed.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal