Back to skill

Security audit

YNAB

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed YNAB connector helper that reads sensitive budget data through OOMOL, with no artifact evidence of hidden exfiltration or destructive behavior.

Install only if you are comfortable letting OOMOL's oo connector access your YNAB data. Treat YNAB budget and transaction data as sensitive, review any generated oo command before it runs, and require explicit confirmation before any write or delete action if the connector later exposes one.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest says the skill is for 'searching and reading data,' but the body explicitly discusses state-changing YNAB actions and how to run them. This mismatch can mislead an orchestrating agent or reviewer into treating the skill as read-only, reducing scrutiny and potentially enabling unintended write operations against a user's financial data.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger text says to use this skill for 'ANY YNAB request' and 'instead of calling the API directly,' which is overly broad and can cause the skill to be invoked in situations beyond simple read access. In context, that is more dangerous because the skill documentation also acknowledges potentially state-changing actions, so broad routing increases the chance of unnecessary or risky use.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.