Back to skill

Security audit

RocketReach

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward RocketReach connector helper that uses OOMOL’s CLI for account-connected searches and lookups, with no evidence of hidden or destructive behavior.

Before installing, understand that this skill can query RocketReach through your connected OOMOL account and may expose person, company, and account-profile data available to that account. Only run the setup/login steps when you intend to connect RocketReach, and review any live action schema before sending lookup or search data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
78% confidence
Finding
The safety section asserts that untagged actions are reads and safe to run directly, but the same document also includes operational commands such as CLI installation and `oo auth login` that are not read-only. This can mislead an agent or user into treating the overall skill workflow as harmless, increasing the chance of executing environment-changing commands without adequate confirmation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.