Back to skill

Security audit

Tianyancha

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Tianyancha connector helper that uses OOMOL's oo CLI for read/search company-data actions, with no artifact-backed evidence of hidden or unrelated behavior.

Install only if you intend to let agents query Tianyancha through your OOMOL account. Be aware that setup may require installing the oo CLI, signing in, connecting Tianyancha, and using OOMOL billing; review payloads before any future write or destructive action even though the listed actions here are read/search oriented.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description instructs the agent to use this skill for ANY Tianyancha request, which is an overly broad trigger that can cause automatic invocation whenever Tianyancha is merely mentioned. This can lead to unintended tool use, unnecessary external data access, and reduced opportunity for safer or more appropriate handling paths.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.