Back to skill

Security audit

AbuseIPDB

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent AbuseIPDB connector helper that uses OOMOL's CLI and does not show deceptive, hidden, destructive, or exfiltrating behavior.

Install only if you are comfortable connecting AbuseIPDB through OOMOL and allowing the agent to run `oo` connector commands. Review payloads before any action tagged `[write]`, and install or sign in to the `oo` CLI only when you intentionally want to use this integration.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill documents `check_block` as merely inspecting a CIDR block, yet simultaneously tags it as a `[write]` action. This contradiction can cause an agent or operator to misclassify a potentially state-changing operation as read-only, increasing the risk of unintended external side effects without appropriate user confirmation.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill instructs agents to use it for any AbuseIPDB-related request, creating an overly broad routing trigger with no narrowing conditions or exclusions. Broad triggers can cause unnecessary delegation to this skill for sensitive or ambiguous tasks, increasing the chance of unintended command execution, misuse of connected credentials, or bypass of more context-appropriate safeguards.

Static analysis

No suspicious patterns detected.