Back to skill

Security audit

OpenMandate

Security checks across malware telemetry and agentic risk

Overview

This skill appears legitimate and purpose-aligned, but it gives agents direct authority to make irreversible OpenMandate account and matching changes without clear confirmation guardrails.

Install only if you intend to let an agent manage OpenMandate records. Before use, instruct the agent to ask for explicit confirmation before deleting contacts, closing mandates, accepting matches, or submitting final outcomes, and to show the exact contact, mandate, or match ID plus the consequence of the action before proceeding.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill documents irreversible operations like deleting contacts and closing mandates without instructing the agent to obtain explicit user confirmation or warn about permanence. In an agentic workflow, this increases the chance of accidental destructive actions that can remove user data or terminate matching activity without recourse.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill encourages sending email addresses, OTP-related identifiers, mandate content, and later revealed contact details to a third-party service without any privacy or data-sharing notice. Users may unknowingly disclose personal or commercially sensitive information to OpenMandate, creating consent, confidentiality, and compliance risks.

Missing User Warnings

Low
Confidence
86% confidence
Finding
The Close Mandate endpoint performs an irreversible state-changing action that stops the agent working on the user's behalf, but the reference does not include an explicit caution to require user confirmation before calling it. In an agent-integrated context, this increases the risk of accidental or overly eager closure triggered by ambiguous instructions, automation bugs, or prompt manipulation.

Missing User Warnings

Low
Confidence
83% confidence
Finding
The match flow states that counterparty contact information is revealed after both parties accept, but it does not prominently warn that this is a privacy-impacting disclosure. In agent workflows, lack of a warning can cause users or agents to accept matches without understanding that personally identifying contact data will be shared.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.