Back to skill

Security audit

AiVOOV

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently provides AiVOOV voice/audio actions through the OOMOL oo CLI and does not show hidden or unrelated behavior.

Install this only if you intend to use AiVOOV through OOMOL. Review the oo CLI installer and OOMOL account connection flow, and confirm any `create_audio` payload before allowing it to run because it is a write action that may consume account credits.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger description is extremely broad: it instructs the agent to use this skill for ANY AiVOOV request and instead of calling the API directly. That can cause over-invocation on vague mentions of AiVOOV, expanding the skill’s authority unnecessarily and increasing the chance of unintended reads or writes through the connected account.

Static analysis

No suspicious patterns detected.