Back to skill

Security audit

Felt

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly disclosed Felt connector wrapper that can read, create, update, and delete Felt data through OOMOL, with confirmation required for changes and deletions.

Install only if you want an agent to operate your Felt account through OOMOL. Review write and delete payloads carefully before approving them, and verify the oo CLI install URL before running the first-time setup command.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description uses an absolute routing instruction ('Use this skill for ANY Felt request') that can override narrower, safer task handling and encourage indiscriminate delegation of all Felt-related operations to a shell-capable connector wrapper. In a skill that exposes read, write, and destructive actions, this broad trigger increases the chance of unintended invocation, including for sensitive or destructive operations, especially if downstream agents treat the phrase as authoritative.

Static analysis

No suspicious patterns detected.