Back to skill

Security audit

HigherGov

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent read-only HigherGov connector skill, with disclosed use of the OOMOL oo CLI and no hidden persistence or destructive behavior.

Before installing, confirm you are comfortable routing HigherGov searches through OOMOL's oo CLI and connected account. The skill appears read-only, but first-time setup may require installing the oo CLI and connecting a HigherGov API key in OOMOL.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation text directs the agent to use this skill for "ANY HigherGov request," which is broader than necessary and can cause the skill to intercept a wide range of ordinary HigherGov-related tasks without clear boundaries. In an agent setting, overly broad routing increases the chance of unnecessary tool execution and reduces opportunities for the model to apply narrower safety or least-privilege decision-making.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.