Back to skill

Security audit

Cyberimpact

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Cyberimpact connector skill that can read and change Cyberimpact data, with no evidence of hidden behavior or malware.

Install this only if you want your agent to operate Cyberimpact through OOMOL. Review payloads before approving create, update, replace, or delete actions, and be especially careful with member lists, templates, and group deletion because those affect business contact data.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description and frontmatter instruct the agent to use this skill for ANY Cyberimpact-related request, which is an overly broad routing rule. This can cause the agent to invoke a powerful integration for loosely related prompts, increasing the chance of unintended data access or state-changing operations without sufficient contextual narrowing.

Static analysis

No suspicious patterns detected.