Render

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Render management connector; it can affect live services, so users should confirm service-changing actions before use.

Install only if you intend to let an agent manage your Render account through OOMOL. Before restart, suspend, resume, rollback, or deploy actions, confirm the exact service, workspace, payload, and production impact; also make sure you trust the oo CLI and OOMOL account connection used to hold Render credentials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation description is unusually broad: it directs the agent to use this skill for ANY Render-related request, including reading, creating, and updating data. That can cause over-activation and route tasks into a high-privilege connector path even when direct clarification or a narrower tool would be safer, increasing the chance of unintended state-changing actions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This action documentation exposes a destructive operation ('Suspend a Render service') but provides no warning about service downtime, production impact, or the need for explicit user confirmation before execution. In an agent-driven context, sparse instructions around destructive actions increase the chance of accidental suspension of live services, especially because the skill is framed as the default path for any Render request.

VirusTotal

47/47 vendors flagged this skill as clean.

View on VirusTotal