Back to skill

Security audit

Avoma

Security checks for vulnerabilities and agentic risk

Overview

This Avoma skill is a disclosed read-only connector workflow, with some normal privacy caution because meeting transcripts and recordings can be sensitive.

Install this only if you are comfortable letting the agent query Avoma data through your connected OOMOL account. Be specific about meeting IDs, date ranges, users, or filters when asking for data so it does not retrieve more transcripts, recordings, or user information than needed.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrase is extremely broad: it instructs use of the skill for ANY Avoma-related request, which can cause the agent to invoke this skill even when a more precise workflow or direct user clarification would be safer. In a connector-backed skill, over-invocation increases the chance of unnecessary access to meeting, transcription, recording, or user data and can lead to accidental disclosure or retrieval beyond the user's actual intent.

Static analysis

No suspicious patterns detected.