Back to skill

Security audit

noCRM.io

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent noCRM.io connector, but it gives agents CRM write/delete capability and mislabels some state-changing actions as safe to run without confirmation.

Review before installing. Use it only if you want an agent to operate your connected noCRM.io account through OOMOL. Require explicit confirmation for every action that changes leads, including appending descriptions and changing status, not only the actions marked [write] or [destructive]. Do not run the remote CLI install commands unless you trust OOMOL and intend to set up the connector.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description instructs the agent to use this skill for ANY noCRM.io request, which creates an overly broad trigger surface. In practice, that can cause the skill to activate on incidental mentions of noCRM.io and route user intent into a high-privilege integration capable of reads, writes, and deletions without sufficient narrowing or preconditions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.