Back to skill

Security audit

EasyPost

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed EasyPost connector wrapper with limited `oo` CLI access and user confirmation requirements for state-changing actions.

Install this only if you intend to manage EasyPost through OOMOL's `oo` CLI. Review write payloads carefully before approving address or tracker creation, and only run the CLI install or account-connection steps if you trust OOMOL and understand that EasyPost access will be mediated through that connected account.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill instruction to use this skill for ANY EasyPost request is overly broad because it can suppress normal tool-selection safeguards and route all EasyPost-related tasks through a single connector without evaluating whether the request is appropriate, least-privileged, or safe. In a security context, broad mandatory routing increases the chance of unintended writes, data exposure, or abuse if the skill is invoked for sensitive or ambiguous requests.

Static analysis

No suspicious patterns detected.