Back to skill

Security audit

HR Partner

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed HR Partner connector for reading HR and recruiting records, with no artifact evidence of hidden or destructive behavior.

Install this only if you trust OOMOL's oo CLI and connector service with your HR Partner account, and ensure the connected HR Partner credentials are scoped for users who are allowed to view employee and recruiting records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill metadata promises only searching and reading, but the body explicitly discusses possible `[write]` and `[destructive]` actions through the same connector. That mismatch can cause an agent or reviewer to grant trust based on the manifest while still exposing state-changing operations, increasing the risk of unintended or unauthorized modifications if additional actions are later added or invoked.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to use this skill for ANY HR Partner request, which is a broad routing rule that can cause the skill to be invoked for tasks beyond narrow read-only employee lookup. In context, the skill interfaces with sensitive HR data, so overbroad invocation increases the chance of unnecessary access, data exposure, or accidental execution in situations where a more constrained tool or additional user confirmation would be safer.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.