Back to skill

Security audit

Agora

Security checks for vulnerabilities and agentic risk

Overview

This Agora skill is a disclosed connector wrapper with powerful but purpose-aligned project and certificate actions that require user confirmation before changes.

Before installing, make sure you want an agent to manage Agora projects through your connected OOMOL account. Treat create, status changes, certificate enable/disable, and certificate reset as sensitive operations, and only approve them after checking the exact project and payload.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill advertises itself as the handler for any Agora-related task, which is an overly broad activation trigger. Broad routing increases the chance the agent will invoke this skill for loosely related requests and expose state-changing or destructive Agora capabilities in contexts where a narrower, read-only, or more specific skill would be safer.

Static analysis

No suspicious patterns detected.