Back to skill

Security audit

GitHub

Security checks across malware telemetry and agentic risk

Overview

This is a broad but clearly disclosed GitHub connector skill with explicit confirmation requirements for changes and destructive actions.

Install only if you want Codex to use your OOMOL-connected GitHub account for repository and account actions. Review exact payloads before approving write actions, be especially careful with destructive actions such as deleting repositories, files, refs, releases, or collaborators, and review the oo CLI installer before running first-time setup.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description says to use this skill for ANY GitHub request, which creates an extremely broad routing trigger with no task-level scope limits. In a skill that exposes many write and destructive GitHub operations, this increases the chance the agent will invoke it for loosely related requests and perform sensitive repository, workflow, or account actions without sufficiently narrowing intent first.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.