Back to skill

Security audit

Pushover

Security checks across malware telemetry and agentic risk

Overview

The skill mostly matches its Pushover purpose, but it under-labels credential-returning and authentication-related actions as safe reads.

Install only if you are comfortable giving the skill access to your Pushover-connected OOMOL account. Before using it, require explicit confirmation for any action that returns or stores tokens, logs in a client, opens a client session, sends messages, changes groups or teams, or deletes/acknowledges messages; do not treat all untagged actions as safe reads.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The safety section incorrectly states that untagged actions are read-only, but the listed untagged actions include credential-revealing and state-changing/authentication operations such as get_app_token, get_team_api_token, client_login, store_team_api_token, and subscription_flow. This misclassification can cause an agent to execute sensitive actions without confirmation, exposing secrets or altering authentication state under the assumption that they are safe reads.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description says to use this skill for ANY Pushover request and whenever a task involves Pushover, which is overly broad routing guidance. In an agentic environment, this can cause the skill to activate for incidental mentions of Pushover and then expose powerful actions, including destructive or credential-related ones, in contexts where a narrower tool-selection policy would be safer.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.