Back to skill

Security audit

Data247

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Data247 connector skill that discloses its use of the OOMOL oo CLI and does not contain hidden code or destructive behavior.

Install only if you intend to use OOMOL as an intermediary for Data247 lookups. Treat phone numbers and names as sensitive data, confirm you are comfortable sending them through the oo connector, and review the oo CLI installer and account connection flow before first use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The instruction to use this skill for ANY Data247 request is an overly broad activation condition that can cause the skill to be invoked whenever Data247 is merely mentioned, even if the user did not intend to use the connector. This can lead to unnecessary external data access, accidental disclosure of user-provided identifiers to a third-party service, and bypass of more context-appropriate handling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.