Back to skill

Security audit

SimplyBook.me

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent SimplyBook.me connector that uses the OOMOL `oo` CLI and includes confirmation guidance for state-changing actions.

Before installing, confirm that you trust OOMOL and want Codex to operate your SimplyBook.me account through the `oo` CLI. Read-only list/get actions are intended to run directly, while any action marked `[write]` or `[destructive]` should be run only after you review the exact payload and effect.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill is declared as the handler for ANY SimplyBook.me request, including reading, creating, and updating data, without narrowing scope by task type, risk level, or user intent. This broad routing increases the chance the skill is invoked for sensitive or state-changing operations by default, which can lead to unintended data access or mutations if downstream safeguards are weak or inconsistently followed.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.