Back to skill

Security audit

Typeform

Security checks across malware telemetry and agentic risk

Overview

This skill is a read-oriented Typeform connector wrapper with disclosed credential requirements and no artifact-backed malicious behavior.

Before installing, understand that this skill lets an agent read data from your connected Typeform account, including form responses, through the OOMOL oo connector. Use it only with a Typeform account whose data you are comfortable exposing to your agent workflow, and be cautious if future versions add write or destructive actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The manifest says the skill is for 'searching and reading data,' but the body explicitly describes support for state-changing actions and gives guidance for running write/destructive operations. This mismatch weakens user and policy expectations, making it easier for an agent or reviewer to trust the skill as read-only when future connector actions could modify or destroy data.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The safety section defines semantics for untagged, [write], and [destructive] actions, but the listed actions have no such tags and the document still implies mutating actions may exist. This creates ambiguity that can cause an agent to infer safety from missing tags rather than from an enforced action allowlist, especially if the live schema exposes additional actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.