Back to skill

Security audit

BoldSign

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed BoldSign connector wrapper with read actions and one clearly marked write action requiring user confirmation.

Install this only if you trust OOMOL’s `oo` CLI and are comfortable letting the skill read BoldSign documents/templates and send signature requests from templates when you explicitly confirm the payload and effect.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill explicitly claims it should be used for ANY BoldSign request, which creates an overly broad trigger scope and can cause the agent to invoke this skill in situations where a narrower, more context-specific workflow or additional policy checks would be more appropriate. In this case the skill can perform both read and write operations, so broad routing increases the chance of unnecessary access or unintended state-changing actions being funneled through a single connector.

Static analysis

No suspicious patterns detected.