Back to skill

Security audit

Salesloft

Security checks across malware telemetry and agentic risk

Overview

This Salesloft skill is a disclosed OOMOL CLI integration for reading Salesloft data, with no artifact-backed evidence of hidden writes or malicious behavior.

Before installing, understand that this skill lets the agent query Salesloft data through your OOMOL-connected account and may require a one-time oo CLI install and OOMOL sign-in. Use normal caution with CRM/business data, and require explicit confirmation before allowing any future connector action that writes, deletes, or changes Salesloft records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The manifest and description frame the skill as limited to searching and reading data, but the body explicitly supports running arbitrary connector actions and discusses state-changing operations. This mismatch can cause an orchestrator or user to invoke the skill under a read-only assumption, increasing the risk of unintended writes if additional actions are exposed by the connector.

Intent-Code Divergence

Low
Confidence
84% confidence
Finding
The safety section describes write and destructive tags as safeguards, but the listed actions include no such tags, leaving readers to trust that all untagged actions are reads. If the connector later exposes or renames mutating actions without accurate tagging, the documentation can mislead an agent into executing state-changing operations without appropriate confirmation.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The trigger phrase says to use this skill for ANY Salesloft request, which is broader than the stated purpose of searching and reading data. This can route unrelated or potentially sensitive Salesloft tasks through a skill whose boundaries are ambiguous, increasing the chance of misuse or over-privileged action selection.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.