Back to skill

Security audit

Gotify

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Gotify connector wrapper with disclosed read and send-message actions, though users should confirm any message before it is sent.

Install this only if you intend to use OOMOL's oo CLI with your Gotify account. Review the oo CLI installer and account connection flow, and require the agent to show and confirm the exact message payload before using send_message.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The description says to use this skill for ANY Gotify request and instead of calling the API directly, which can cause the agent to invoke the skill on broad or incidental Gotify-related mentions without sufficient task scoping. In practice, this increases the chance of unnecessary connector execution and, because the skill includes a write-capable action (`send_message`), can lead to unintended state-changing operations if higher-level confirmation logic is weak or bypassed.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.