Back to skill

Security audit

ShipEngine

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward ShipEngine connector skill, with expected credentialed API use and no hidden code or destructive behavior in the artifact.

Install only if you are comfortable letting the agent use your OOMOL-connected ShipEngine account for rate, carrier, address parsing, and address validation requests. Review payloads that include customer addresses or shipment details, and treat rate/validation calls as external API activity that may affect usage or billing even when they do not buy labels or modify shipments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The manifest and description claim the skill is for 'searching and reading data', but the documented actions include operations such as rate calculation/estimation that trigger outbound requests and may incur cost or operational side effects. This mismatch can cause downstream agents or users to treat the skill as read-only and invoke it without the confirmation safeguards normally applied to non-read actions.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The instruction to use this skill for 'ANY ShipEngine request' is an overly broad routing directive that can override more specific safety-aware handling. In agentic systems, broad trigger phrases increase the chance of inappropriate invocation for sensitive, state-changing, or higher-risk tasks without evaluating whether this skill is the safest execution path.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.