Shipday

Security checks across malware telemetry and agentic risk

Overview

This Shipday skill gives an agent disclosed access to manage Shipday orders through OOMOL, with clear confirmation rules for write and delete actions.

Install this only if you want an agent to access your Shipday account through OOMOL. Review the connected Shipday API key scopes, confirm exact payloads before creating or editing orders, require explicit approval before deleting orders, and only run the oo CLI installer from OOMOL if you trust that source.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill labels `get_order` and `get_order_progress` as `[write]` even though they are described as retrieval operations. This contradicts the safety model and can cause the agent to apply the wrong confirmation policy, either creating unnecessary friction or, more importantly, normalizing inaccurate risk labeling that undermines trust in the action catalog.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest says to use this skill for "ANY Shipday request" and instead of calling the API directly, which is an overly broad routing instruction. Broad triggers increase the chance the skill is invoked in inappropriate contexts, including sensitive or destructive operations, without narrowing conditions or extra safeguards.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal