Back to skill

Security audit

MaintainX

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed MaintainX connector skill that can read and change MaintainX data, with visible confirmation guidance and no hidden bundled code.

Install only if you want the agent to operate your MaintainX account through OOMOL. Require explicit confirmation before creating or updating records, creating users, changing work order status, posting comments, or deleting a location, and review the oo CLI install and OOMOL connection steps before approving them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description instructs the agent to use this skill for "ANY MaintainX request" and instead of calling the API directly, which is an overly broad routing trigger. Broad invocation criteria can cause the skill to capture unrelated or sensitive tasks too aggressively, increasing the chance of unintended execution paths, over-privileged connector use, or bypass of more appropriate safeguards in other workflows.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal