Back to skill

Security audit

Mixmax

Security checks across malware telemetry and agentic risk

Overview

This Mixmax skill is a disclosed OOMOL connector wrapper with limited listed actions and explicit confirmation requirements for state-changing use.

Before installing, understand that this skill can use your connected Mixmax account through OOMOL and can add recipients to sequences when you approve the exact payload. Read/search actions are intended to run directly, while write actions should only proceed after you confirm the target and effect.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill explicitly says to use it for ANY Mixmax request and instead of calling the API directly, which creates an overly broad trigger scope. This can cause the agent to invoke a high-privilege integration for loosely related requests, increasing the chance of unintended data access or state-changing operations without sufficiently precise routing boundaries.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.