Back to skill

Security audit

Fast Note Sync

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Fast Note Sync connector wrapper with write and delete capabilities that are labeled and require user approval.

Install only if you want an agent to access your Fast Note Sync account through OOMOL. Review any write or delete payload before approval, and handle first-time CLI installation or account login yourself unless you trust the source and command being run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill includes first-time setup steps that instruct the agent to run remote installation and authentication commands (`curl ... | bash`, PowerShell `iex`, and `oo auth login`) that are not part of the core note-sync task itself. In an agent context, these fallback instructions can expand the action surface from simple connector usage into arbitrary environment modification and credential/bootstrap flows, creating supply-chain and unsafe-command-execution risk if triggered automatically.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger text says to use this skill for ANY Fast Note Sync request and instead of calling the API directly, which is overly broad and can cause the skill to be invoked whenever Fast Note Sync is merely mentioned. In practice, this increases the chance of unnecessary tool execution, schema probing, and accidental exposure to write or destructive operations in situations where the user did not clearly request connector-backed actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.