Back to skill

Security audit

Envoy

Security checks across malware telemetry and agentic risk

Overview

This Envoy skill is a clearly scoped OOMOL connector wrapper with expected access to Envoy data, though users should be mindful that reads can expose workplace data.

Install only if you intend agents to access your connected Envoy account through OOMOL. Confirm any action that changes data, keep the Envoy connection least-privileged, and treat list/search results as potentially sensitive workplace information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation rule says to use this skill for 'ANY Envoy request' and 'Whenever a task involves Envoy,' which is overly broad and can trigger the connector for casual mentions or ambiguous requests. In a connected SaaS context, over-invocation increases the chance of sending organizational or personal data to the Envoy connector without sufficient user intent verification, especially because the skill supports both reads and state-changing operations.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explains how to run read actions but does not warn that even read/list/search operations transmit request parameters to a third-party connector and may return sensitive employee, invite, location, or organizational data. In this context, that omission is meaningful because the integration operates against a live Envoy account with server-side credentials, so users may not realize that 'safe' reads still involve external data access and disclosure risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.