Back to skill

Security audit

Box

Security checks for vulnerabilities and agentic risk

Overview

This Box skill is broad but clearly disclosed, purpose-aligned, and includes confirmation requirements for write and destructive actions.

Before installing, understand that this skill can access and change Box content available to your connected OOMOL account. Read-only Box requests may run directly, while uploads, updates, and deletes should be confirmed with exact targets and effects before execution.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to use it for ANY Box-related request, which creates an overly broad routing scope. This can cause the agent to invoke Box capabilities in contexts where narrower intent checking, least-privilege handling, or extra confirmation would be more appropriate, increasing the chance of unintended data access or state-changing operations.

Static analysis

No suspicious patterns detected.