Back to skill

Security audit

Dandelion API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Dandelion text-analysis connector that sends user-provided text through OOMOL, with no hidden persistence or destructive behavior found.

Install this only if you are comfortable sending selected text to Dandelion through OOMOL. Avoid using it on sensitive text unless that external processing is intended, and treat the one-time CLI install/login steps as account setup that should be reviewed before running.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger text is overly broad because it instructs use of this skill for ANY Dandelion API request and whenever a task involves Dandelion API, which can cause the agent to invoke the skill even when a more constrained or context-appropriate path would be safer. In practice this increases the chance of unintended external API calls, unnecessary data disclosure to the connector, and reduced user control over when third-party access occurs.

Static analysis

No suspicious patterns detected.