Back to skill

Security audit

Beehiiv

Security checks for vulnerabilities and agentic risk

Overview

This Beehiiv connector skill is purpose-aligned and disclosed, with normal integration risks around sending Beehiiv data through OOMOL.

Install this only if you intend to let OOMOL act as the connector between your agent and Beehiiv. Treat subscriber lists, publication data, and draft or post content as sensitive, review payloads before write actions, and only run the one-time CLI install or account connection steps when you actually need the integration.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The instruction to use this skill for ANY Beehiiv request creates overly broad routing and weak scope boundaries. That increases the chance an agent will invoke the skill for ambiguous mentions, causing unnecessary external data access or transmission when a narrower, safer path would suffice.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill tells the agent to send JSON payloads to the `beehiiv` connector but does not clearly warn that user-provided Beehiiv data will be transmitted to an external service. This can lead to inadvertent disclosure of sensitive publication, subscriber, or content data without informed user awareness.

Static analysis

No suspicious patterns detected.