Back to skill

Security audit

Botsonic

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Botsonic connector that uses OOMOL's oo CLI for read-oriented Botsonic actions, with no artifact-backed evidence of hidden, destructive, or unrelated behavior.

Install only if you trust OOMOL and want your agent to access Botsonic through OOMOL's oo connector. Treat Botsonic conversations and FAQs as sensitive account data, and use the skill for explicit Botsonic tasks rather than casual mentions. Review any CLI install or login step before running it.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger text says to use this skill for ANY Botsonic request and to prefer it over calling the API directly, which is an overly broad invocation condition. Broad routing language can cause the agent to invoke the skill in situations where Botsonic is only tangentially mentioned, increasing the chance of unnecessary external data access, unintended connector use, or bypass of more task-specific safeguards.

Static analysis

No suspicious patterns detected.