Back to skill

Security audit

Omem

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local work-memory search wrapper, but users should understand it can query sensitive emails, documents, calendar items, and notes.

Install this only if you want your agent to search an existing OMem index that may include work email, calendars, documents, and notes. For ambiguous requests, be aware the skill encourages querying first; consider giving explicit boundaries such as which account, source, date range, or document type to search.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill instructs the agent to use OMem whenever a question even implicitly touches work context and explicitly says to query first when in doubt. Because OMem searches across highly sensitive local sources like email, calendars, documents, and collaboration notes, this broad trigger guidance can cause unnecessary access to private work data for ambiguous prompts, increasing the chance of over-collection and data exposure beyond what is needed to answer the user's request.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger section uses expansive language like 'ANY of' and 'When in doubt, call it,' which biases the agent toward invoking a sensitive local-memory search tool even for weak or indirect signals. In the context of a skill that can surface emails, meetings, files, and notes, this increases the risk of privacy-invasive retrieval, unintended disclosure in responses, and unnecessary processing of sensitive enterprise data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.