Back to skill

Security audit

Cronly

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Cronly connector that can read and change Cronly data through OOMOL, with explicit confirmation rules for write and delete actions.

Install this only if you intend to let your agent operate your connected Cronly account through OOMOL. Review write and delete requests carefully, confirm exact targets before approving them, and only run the CLI install or login steps when you requested setup or a command actually fails for that reason.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest description instructs the agent to use this skill for ANY Cronly request, which is an overly broad trigger that can cause the skill to activate for all Cronly-related tasks without sufficient narrowing by operation type or risk level. In context, this increases the chance that sensitive write or destructive actions are routed through the skill automatically, relying only on in-skill guidance for confirmation rather than stronger invocation scoping.

Static analysis

No suspicious patterns detected.