Back to skill

Security audit

Cochrane

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-oriented Cochrane connector wrapper with disclosed setup and credential handling, though its trigger wording is broader than its listed actions.

Install only if you are comfortable using OOMOL’s oo CLI and connecting your Cochrane account through OOMOL. Treat it as suitable for reading listed Cochrane review data, and be cautious if future connector actions add write or destructive capabilities.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger text instructs the agent to use this skill for "ANY Cochrane request," which is broader than the actual documented capabilities of the skill. This can cause over-routing of tasks to a connector without sufficient scoping or policy checks, increasing the chance the agent will invoke external tooling for requests that should be handled differently or require additional user confirmation.

Static analysis

No suspicious patterns detected.