Rocketlane

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Rocketlane read-only connector that uses OOMOL's oo CLI and does not show hidden, destructive, or exfiltrating behavior.

Install this only if you want your agent to read Rocketlane project, task, and user data through an OOMOL-connected account. Review the OOMOL CLI and Rocketlane connection setup before authorizing credentials, and prefer using the skill for explicit Rocketlane data lookup tasks rather than casual mentions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The description says to use this skill for ANY Rocketlane request and whenever a task involves Rocketlane, which is an overly broad trigger that can cause the agent to invoke the skill for casual mentions or tasks better handled another way. Over-broad routing increases the chance of unintended data access, unnecessary external calls, and bypass of more context-appropriate controls.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal