Back to skill

Security audit

TimelinesAI

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward TimelinesAI connector that can read chats and send WhatsApp messages, with write actions disclosed and confirmation required.

Install only if you intend to let the agent operate your TimelinesAI workspace through OOMOL. Review outbound WhatsApp message details carefully before approval, and be aware that read actions may expose chat, message, workspace, and connected-account information to the agent during requested tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description says to use this skill for ANY TimelinesAI request and instead of calling the API directly, which can cause the agent to invoke the skill too broadly whenever TimelinesAI is merely mentioned. Because this skill includes write-capable actions such as sending messages, overbroad routing increases the chance of unintended activation and accidental state-changing operations in the wrong context.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.