Back to skill

Security audit

Ayrshare

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Ayrshare connector helper, with no artifact evidence of hidden behavior or data misuse.

Install only if you want Codex to operate your Ayrshare-connected social posting account through OOMOL. Review payloads carefully before publishing, updating, retrying, or deleting posts, because those actions can affect public or scheduled social media content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill marks several apparently read-oriented actions such as `get_post`, `get_post_analytics`, and `list_post_history` as `[write]`, while later stating that untagged actions are reads. This contradictory safety labeling can mislead an agent or user about which operations require confirmation, increasing the chance of unnecessary blocking of safe reads or, more importantly, incorrect trust in the documentation’s safety model when deciding whether a command changes state.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger scope instructs the agent to use this skill for ANY Ayrshare-related request instead of calling the API directly, which is broader than necessary. Overly broad routing can cause the skill to be invoked in situations where a narrower tool or direct reasoning would be safer or more appropriate, expanding the blast radius of any mistakes in the skill’s instructions or action classifications.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.