Back to skill

Security audit

Loyverse

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Loyverse read-only connector helper, with a minor scoping note around broad routing language.

Install only if you intend to use OOMOL's oo CLI with a connected Loyverse account. Treat it as a read-only Loyverse lookup helper; confirm manually before any setup, billing, authentication, or future state-changing connector action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The instruction to use this skill for 'ANY Loyverse request' is overly broad and can cause an agent to invoke it whenever Loyverse is mentioned, even when the request is outside the skill's real scope. In an agentic environment, overbroad routing language increases the chance of unintended command execution paths, unnecessary credentialed access attempts, or bypass of more appropriate tools.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.