Back to skill

Security audit

CrateDB Cloud

Security checks across malware telemetry and agentic risk

Overview

This skill is a read-oriented CrateDB Cloud connector with disclosed OOMOL setup guidance and no artifact evidence of hidden, destructive, or unrelated behavior.

Install only if you intend to let an agent read CrateDB Cloud account and resource information through OOMOL. Review any first-time CLI installer or login step before allowing it, and require explicit confirmation before any future connector action that is not one of the documented get/list reads.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

High
Confidence
86% confidence
Finding
The manifest and description present the skill as being for 'searching and reading data', but the document also includes setup operations and safety guidance for potential write/destructive actions. This creates a trust-boundary mismatch: an agent or reviewer may assume the skill is read-only and invoke it under weaker safeguards, increasing the chance of unintended account-affecting or state-changing behavior if additional actions are later exposed through the connector.

Intent-Code Divergence

Medium
Confidence
78% confidence
Finding
The documentation promises that state-changing actions will be marked with '[write]' or '[destructive]', but no such tags appear in the listed actions. This inconsistency can mislead an operator into believing the list is fully classified, weakening review and confirmation practices if the connector schema exposes additional actions or if the docs drift from reality.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The instruction to use this skill for 'ANY CrateDB Cloud request' is overly broad and can cause the agent to route loosely related tasks into this skill automatically. In context, that broad routing matters because the skill has connector execution capability and includes setup/auth guidance, so over-invocation increases the chance of unnecessary account interaction, data exposure, or misuse beyond the user's actual intent.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.