Back to skill

Security audit

Imgix

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Imgix connector skill with disclosed read, write, and cache-purge actions, and no evidence of hidden behavior or exfiltration.

Install this if you want Codex to manage Imgix through OOMOL. Be aware it can update Imgix sources and purge cached assets when you explicitly approve those actions, and only run the oo CLI installation or account-connection steps if you trust OOMOL and need this integration.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description directs the agent to use this skill for any Imgix-related task instead of calling the API directly, which is an overly broad routing instruction. This can bypass normal tool-selection scrutiny and cause the agent to invoke a write-capable connector in situations where a narrower or safer path would be more appropriate, increasing the chance of unnecessary privileged actions or unintended side effects.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.