Back to skill

Security audit

OneDrive

Security checks across malware telemetry and agentic risk

Overview

This appears to be a disclosed OneDrive connector with broad file access, but the only concern found is overbroad activation wording rather than hidden or malicious behavior.

Install only if you want your agent to operate your OneDrive account. Give explicit file paths and actions, and require confirmation before uploads, overwrites, moves, deletes, sharing changes, or other state-changing operations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description says to use this skill for "ANY OneDrive request," which can cause the agent to route broad or ambiguous tasks into a high-privilege integration without sufficient scoping. Because this skill supports read, write, and destructive actions, overbroad invocation increases the chance of unintended data modification or deletion when a user merely mentions OneDrive contextually.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.