Back to skill

Security audit

Placekey

Security checks across malware telemetry and agentic risk

Overview

This is a clearly scoped Placekey lookup skill that uses OOMOL's CLI and does not include hidden code or unrelated behavior.

Install this only if you are comfortable using OOMOL as the intermediary for Placekey requests and with address/location data being sent through that connector. Review the oo CLI installer before running the optional first-time setup commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description directs the agent to use this skill for ANY Placekey-related request, which is an overly broad trigger that can cause the skill to be invoked in situations the user did not explicitly intend. In agentic systems, such catch-all routing increases the chance of unnecessary external data access or command execution and reduces the user's control over tool selection.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.