Back to skill

Security audit

Avochato

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Avochato connector wrapper that can read messages/contacts and perform confirmed write actions through the oo CLI.

Install this only if you want an agent to access your Avochato account through OOMOL. Treat contact and message data as sensitive, and review exact payloads before approving send_message or upsert_contact actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description says to use this skill for ANY Avochato request, which creates an overly broad trigger boundary and can cause the agent to route all Avochato-related tasks through a high-privilege integration without first narrowing the user’s intent. In context, this is more dangerous because the same skill exposes both read and write actions, so an overly eager invocation increases the chance of unintended state-changing operations or unnecessary exposure of contact/message data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.