Back to skill

Security audit

Adyntel

Security checks for vulnerabilities and agentic risk

Overview

This is a small, disclosed Adyntel connector skill that performs read-oriented ad intelligence lookups through the OOMOL `oo` CLI, with no evidence of hidden persistence, credential theft, destructive behavior, or unrelated access.

Install this if you are comfortable using OOMOL’s `oo` CLI and connected Adyntel account for ad-library and keyword lookups. For vague Adyntel-related requests, ask the agent to confirm before sending queries externally, and review the `oo` CLI installer source before running the first-time setup command.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation text says to use this skill for ANY Adyntel request and instead of calling the API directly, which is overly broad and can cause the agent to select this skill for loosely related queries without sufficient user intent validation. In practice this increases the chance of unintended external data access or unnecessary tool execution, even though the listed actions are read-oriented.

Static analysis

No suspicious patterns detected.