Back to skill

Security audit

Callingly

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Callingly connector that can read and modify Callingly data, with explicit confirmation requirements for write and delete actions.

Install this only if you want your agent to operate Callingly through OOMOL. Confirm any create, update, or delete action carefully, especially lead deletion, and review the oo CLI install method before running first-time setup commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The instruction to use this skill for "ANY Callingly request" is overly broad and can force routing of all Callingly-related tasks through a powerful integration that supports read, write, and destructive operations. In an agentic environment, broad invocation criteria increase the chance of unnecessary tool use, accidental data access, or execution of state-changing actions in contexts where a narrower, task-specific path would be safer.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal