Back to skill

Security audit

Goody

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Goody connector wrapper that uses the OOMOL CLI with user-connected credentials and includes confirmation guidance for write or destructive actions.

Install this only if you want Codex to operate your Goody account through OOMOL. Review payloads before approving any write or destructive action, and only complete the OOMOL/Goody connection if you trust that integration with the account data it can access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The description says to use this skill for 'ANY Goody request,' which can cause overbroad routing and automatic invocation for all Goody-related tasks without sufficient narrowing by operation type or risk. In practice, that increases the chance an agent will use this skill in inappropriate contexts, including sensitive write-capable workflows, especially because the skill also contains setup and command-execution guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.