Back to skill

Security audit

Appcircle

Security checks across malware telemetry and agentic risk

Overview

This skill coherently provides read-only Appcircle listing actions through the OOMOL `oo` connector, with disclosed setup and safety guidance.

Before installing, users should understand this depends on the OOMOL `oo` CLI and an OOMOL-connected Appcircle account. The current skill only lists Appcircle organizations and profiles, and any future connector action marked write or destructive should require explicit confirmation before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The manifest says the skill is for 'searching and reading data', but the body explicitly discusses `[write]` and `[destructive]` actions and how to run them. That mismatch can mislead an orchestrating agent or user into treating the skill as read-only when it may invoke state-changing operations, increasing the risk of unintended modifications.

Intent-Code Divergence

Low
Confidence
70% confidence
Finding
The safety model depends on tags to distinguish read, write, and destructive actions, but the document also frames the listed actions as a current set rather than a hard allowlist. If new or undocumented connector actions exist and are untagged here, an agent may incorrectly assume they are safe reads and execute them without confirmation.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The trigger instruction says to use this skill for 'ANY Appcircle request' and 'instead of calling the API directly,' which is overly broad. Broad invocation criteria can cause agents to route unrelated or higher-risk Appcircle tasks through this skill by default, including operations the skill may not safely constrain or accurately describe.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.