Back to skill

Security audit

Famulor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a broad but coherent Famulor workspace connector that discloses sensitive capabilities and repeatedly requires scoped access, live schema checks, and explicit approval for high-impact actions.

Install this only if you intend your agent to operate a Famulor workspace. Review the OAuth scopes and workspace role carefully, and require explicit confirmation before messages, calls, campaigns, billing changes, API-key/session changes, phone-number actions, exports, migrations, or unattended routines.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
, voices, reusable tools, bookings, tests, and integrations | 87 | [assistants](references/toolsets/assistants.md) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
| `calls` | Calls, unified history, transcripts, QA, callbacks, and live control | 26 | [calls](references/toolsets/calls.md) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
| `campaigns` | Campaigns, Audience contacts, leads, segments, consent records, and suppression | 32 | [campaigns](references/toolsets/campaigns.md) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
| `messaging` | WhatsApp, Messenger, email, Slack, connectors, templates, and sender profiles | 46 | [messaging](references/toolsets/messaging.md) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
| `telephony` | Phone numbers, SIP trunks, caller IDs, carriers, and number verification | 70 | [telephony](references/toolsets/telephony.md) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
| `automations` | Automations, connections, CRM sync, routines, and runs | 41 | [automations](references/toolsets/automations.md) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
| `settings` | Account, workspaces, API keys, retention, memory, domains, and sessions | 33 | [settings](references/toolsets/settings.md) |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/toolsets/messaging.md (reported line 36)May include surrounding context.

md
| `list_email_senders` | Read-only | `settings:read or assistants:read` | Immediate | List the secrets-free sender choices available to reusable send_email tools: the platform mail server, and verified assistant email addresses. Also returns the workspace display-name and signature defaults. |
| `list_messaging_connector_watch_options` | Read-only | `assistants:read` | Immediate | List Gmail labels or Outlook/Zoho Mail folders a connected mailbox can watch. Same as GET /api/v1/messaging-connectors/{id}/watch-options. Pass a returned id and name when updating the connector to watch a specific label or folder. |
| `list_messaging_connectors` | Read-only | `assistants:read` | Immediate | List messaging bots (Telegram, Slack, Messenger, Teams, Discord, Google Chat, X, WhatsApp, Freshdesk, Gmail, Outlook, Zendesk, ServiceNow, Intercom, Zoho Mail, AgentMail, Instagram, Zulip) linked to assistants. Includes conversation settings and WhatsApp flags when present. |
| `list_messenger_facebook_pages` | Write/action | `assistants:write` | Immediate | List the Facebook Pages a user access token (from Facebook Login on your own frontend) can manage. Returns only page IDs and names. Complete the connector with the original access_token plus the selected page_id; page credentials are never returned. Same as POST /api/v1/messenger/facebook-login/pages. Platform-root workspaces only. The access token is never logged. |
| `list_whatsapp_template_library` | Read-only | `assistants:read` | Immediate | List safe, pre-written utility templates from Meta's official template library for one sender. |
| `list_whatsapp_templates` | Read-only | `assistants:read` | Immediate | List WhatsApp HSM message templates for the workspace. Same as GET /api/v1/whatsapp/templates. |
| `manage_whatsapp_calling` | Write/action | `assistants:write` | Immediate | Change WhatsApp Cloud API calling settings for a connector. enable_calling turns on Meta call settings for the number; resubscribe re-subscribes the
...[truncated 25 chars]

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/toolsets/assistants.md (reported line 14)May include surrounding context.

md
| Tool | Effect | Accepted scope | Execution | Purpose snapshot |
| --- | --- | --- | --- | --- |
| `attach_sms_registration_number` | Write/action | `phone_numbers:write` | Immediate | Attach another purchased US local SMS number in this workspace to its paid approved registration. Confirm the business, message purpose and consent process are the same. Does not create another subscription. |
| `book_meetergo_appointment` | Write/action | `integrations:write` | Immediate | Book an exact start from get_meetergo_availability after the user confirms the time, name and email. A pending_confirmation result is not confirmed. Never repeat a request with an unknown outcome without checking the calendar. |
| `cancel_booking` | Delete/destructive | `bookings:write or calls:write` | Immediate | Cancel a confirmed booking. Sends a METHOD:CANCEL ICS email to the invitee and removes the pushed external calendar event (best-effort). Idempotent for already-cancelled bookings; bookings that already started cannot be cancelled. |
| `cancel_sms_registration` | Delete/destructive | `billing:write` | Immediate | Stop renewal of the workspace SMS registration subscription at the end of its paid period. Sending on all numbers using this registration ends then. Requires explicit confirmation and a billing administrator. |
| `checkout_sms_registration` | Write/action | `billing:write` | Immediate | Create or resume checkout for the reviewed SMS registration quote. Requires an owner, admin or billing user and explicit acceptance of the one-time and monthly price. Open the returned checkout URL to pay; application submission starts only after verified payment. |

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Line L073 says to write the final prompt in the assistant's primary language unless the user requests another authoring language. This sets a default language behavior without clearly offering the user a language choice first, which can conflict with language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.