Back to skill

Security audit

Autoblogging.ai

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Autoblogging.ai connector wrapper with a small, purpose-aligned action set and explicit confirmation requirements for writes.

Before installing, understand that creating articles may consume Autoblogging.ai or OOMOL credits. Confirm the exact article payload before any create action, and only run the oo CLI install, login, or connection steps if the connector command actually fails and you trust the OOMOL setup path.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger text is overly broad: 'Use this skill for ANY Autoblogging.ai request' can cause the agent to invoke the skill whenever Autoblogging.ai is merely mentioned, rather than when the user explicitly intends connector-backed actions. Because this skill supports write operations such as article creation, over-activation increases the chance of unnecessary tool use, unintended external side effects, and accidental data or credit consumption.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.