Back to skill

Security audit

Evenium

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Evenium connector wrapper that uses the OOMOL CLI and connected account credentials, with no hidden scripts or malware signals found.

Install only if you intend to let an agent use your OOMOL-connected Evenium account. Review the live connector schema before actions, confirm any action tagged as write, and verify the oo CLI installer and OOMOL connection flow from trusted sources before first-time setup.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The skill labels `get_guest_post_status` as a `[write]` action even though its description says it only retrieves status. This mismatch can mislead an agent or user about the side effects of the operation, causing unnecessary confirmation fatigue or, worse, masking the true behavior if the underlying connector actually performs a state-changing operation. In a security-sensitive integration, inaccurate action semantics are dangerous because operators rely on these labels to decide whether execution is safe.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The description instructs the agent to use this skill for ANY Evenium request and instead of calling the API directly, which is overly broad routing guidance. This can cause the skill to be invoked for incidental mentions of Evenium or tasks that do not require connector access, increasing the chance of unnecessary exposure to connected-account data or unintended action execution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.