Back to skill

Security audit

Booqable

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Booqable connector wrapper with disclosed account use and mostly read-oriented actions, though users should review Booqable data access before installing.

Install this only if you want an agent to access your Booqable account through OOMOL. Review requested actions before approving any write or destructive operation, and be aware that customer and order data may be returned through the connector.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The instruction to use this skill for 'ANY Booqable request' is overly broad and encourages routing all Booqable-related tasks through a shell-enabled connector without narrowing scope by least privilege or task type. In an agent setting, broad trigger language can cause over-invocation, including on sensitive or state-changing workflows, increasing the chance of unintended data access or modifications.

Static analysis

No suspicious patterns detected.