Back to skill

Security audit

Altiria

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly disclosed Altiria connector that can read and change account data, with user-confirmation requirements for write and delete actions.

Install only if you want your agent to operate your connected Altiria account through OOMOL. Read-only actions can run directly, but creating or updating contacts, sending SMS messages, and deleting contacts should be done only after you verify the exact payload and target.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description says to use this skill for ANY Altiria request, which creates an overly broad trigger surface and can cause the agent to route all Altiria-related tasks through a high-privilege integration without finer scoping. In context, this skill supports read, write, and destructive actions, so broad invocation increases the chance of unintended state-changing operations being selected or attempted when a narrower, task-specific workflow would be safer.

Static analysis

No suspicious patterns detected.