Back to skill

Security audit

VirusTotal

Security checks across malware telemetry and agentic risk

Overview

This VirusTotal skill is purpose-aligned and cleanly scoped, with one documentation mismatch around confirmation for URL scans and file rescans.

Install only if you intend to let Codex use your OOMOL-connected VirusTotal account. Before running URL scans, file uploads, rescans, comments, or votes, confirm the exact target and remember that submitted URLs or files may be shared with VirusTotal and may consume account quota or credits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The safety section says untagged actions are read-only and safe to run directly, but the listed untagged actions include `scan_url` and `rescan_file`, which initiate submissions or analyses and therefore change external state. This can cause an agent to perform network-affecting or billable operations without the explicit confirmation the document reserves for write actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.