Back to skill

Security audit

Ringba

Security checks across malware telemetry and agentic risk

Overview

This Ringba skill is a coherent OOMOL connector wrapper for reading Ringba data, with no artifact-backed evidence of hidden destructive behavior.

Before installing, understand that this skill can run OOMOL oo connector commands against your connected Ringba account and may require installing/signing into the oo CLI. Use it for account data lookups, and require explicit confirmation before any future connector action that is tagged write or destructive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest and description say this skill is for searching and reading data, but the body explicitly permits arbitrary Ringba connector actions and describes handling of [write] and [destructive] operations. This mismatch can cause an orchestrator or user to invoke the skill under the assumption it is read-only, increasing the risk of unintended state changes if additional mutating actions are exposed by the connector.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The phrase 'Use this skill for ANY Ringba request' is overly broad and can cause automatic routing for all Ringba-related prompts, even when the user only wants general information or when direct API/tool selection would be safer. In context, this broad trigger increases the chance of over-invocation and accidental execution of connector actions, though the listed actions here are primarily read-oriented.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.