Back to skill

Security audit

Rollbar

Security checks across malware telemetry and agentic risk

Overview

This Rollbar skill is a coherent connector wrapper with disclosed credential use and no hidden code, though users should review write actions before approving them.

Install only if you trust OOMOL as the intermediary for your Rollbar connection. Treat read commands as access to potentially sensitive error and project data, and require clear confirmation before allowing any write or destructive connector action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
77% confidence
Finding
The trigger phrase instructs use of this skill for ANY Rollbar request, which is overly broad and can cause the agent to route loosely related tasks into a powerful integration without sufficient narrowing. In a skill that can read project data and potentially perform state-changing operations, overbroad invocation increases the chance of unintended data access or action execution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.