Back to skill

Security audit

Similarweb

Security checks across malware telemetry and agentic risk

Overview

This skill is a read-only Similarweb connector helper, with no artifact-backed evidence of hidden or destructive behavior.

Install if you want an agent to query Similarweb through your OOMOL-connected account. Review the oo CLI install step before running it, connect only the intended Similarweb account, and confirm any future write/destructive connector action if the service adds one later.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description says to use this skill for ANY Similarweb request and instead of calling the API directly, which creates an overly broad routing rule. That can cause an agent to invoke this skill in situations where a narrower, safer, or more context-appropriate mechanism should be used, increasing attack surface and the chance of unintended command execution paths.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.