Back to skill

Security audit

OPM Modeler

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a focused OPM conceptual-modeling guidance skill, with only a minor risk that it may activate on loosely related OPM mentions.

Installers should be aware that the skill may be invoked for broad OPM-related discussions; users who only want it for concrete OPM modeling tasks may prefer tighter trigger wording, but no harmful behavior is evident from the available artifacts.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description is overly broad because it includes catch-all phrasing such as 'anything related to OPM conceptual modeling' and generic references like 'any reference to OPM modeling methodology.' In an agent-routing context, this can cause unintended invocation on loosely related requests, misroute user queries, and unnecessarily expose the skill's strong domain instructions where they do not apply.

Static analysis

No suspicious patterns detected.