Back to skill

Security audit

FinerWorks

Security checks across malware telemetry and agentic risk

Overview

This is a coherent read-only FinerWorks connector skill for catalog and pricing lookups, with no hidden state-changing behavior found.

Install this only if you are comfortable using OOMOL's oo CLI and an OOMOL-connected FinerWorks account for read-only catalog and pricing lookups. Treat the one-time CLI install, login, and provider connection steps as account setup actions you should understand before running.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The manifest description says to use this skill for "ANY FinerWorks request" and "instead of calling the API directly," which is an overly broad invocation trigger. Broad routing language can cause the agent to invoke this skill for loosely related requests, increasing unnecessary tool use and expanding the attack surface if untrusted user input is passed into connector actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.