Back to skill

Security audit

Mux

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Mux connector that can read, create, and delete Mux resources through OOMOL, with sensitive actions disclosed and gated by user confirmation.

Install this only if you intend to let the agent operate your Mux account through OOMOL. Review prompts carefully before approving asset creation, playback ID creation, or permanent asset deletion, and ensure your OOMOL-Mux connection has only the scopes you need.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description instructs the agent to use this skill for any Mux-related request, creating an overly broad routing rule that can bypass more context-specific safety checks or cause the agent to invoke write or destructive capabilities when a narrower tool or additional validation would be more appropriate. In this skill, the risk is elevated because the same skill exposes both read actions and state-changing or destructive actions, so broad auto-selection increases the chance of unsafe operations from ambiguous user prompts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.