Back to skill

Security audit

Splunk HTTP Event Collector

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Splunk HTTP Event Collector connector that can send events, with clear write-confirmation guidance and no hidden files or persistence.

Install only if you intend to use OOMOL to send events to a connected Splunk HTTP Event Collector. Review event payloads before approval because both available actions write data into Splunk, and be aware that first-time setup may require installing and signing into the oo CLI.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger text is explicitly broad: it instructs use of this skill for ANY Splunk HTTP Event Collector request and instead of calling the API directly. That can cause the agent to select this skill in unintended contexts, including ambiguous or mixed Splunk tasks, increasing the chance of accidental data writes through the available send_event/send_raw_event actions.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.