Back to skill

Security audit

Get 笔记

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly disclosed Get 笔记 connector wrapper that can read and modify the user's notes through OOMOL, with explicit safeguards for write and delete actions.

Install this only if you want an agent to operate your Get 笔记 account through OOMOL. Review and approve exact payloads before writes, sharing, tag removal, note deletion/trashing, or knowledge-base changes, and only run the first-time CLI install or auth steps if you trust the OOMOL tooling.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill instructs the agent to use it for ANY Get 笔记 request, which is an overly broad trigger that can capture both harmless read operations and sensitive write or destructive actions. In this skill, the broad routing is made more risky because the skill includes state-changing and destructive capabilities, so an agent may invoke it too readily and then rely on in-skill guidance rather than applying narrower task-specific safety checks.

VirusTotal

48/48 vendors flagged this skill as clean.

View on VirusTotal