Back to skill

Security audit

Findymail

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Findymail connector that uses OOMOL's oo CLI for disclosed search and verification actions, with no artifact-backed evidence of hidden or destructive behavior.

Install only if you intend to let the agent query Findymail through your OOMOL account. Be aware that searches and email verification may consume Findymail/OOMOL credits and return professional contact data, and the first-time CLI install/auth steps should only be run when setup is actually needed.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger text says to use this skill for ANY Findymail request and whenever a task involves Findymail, which is broader than a narrowly scoped capability declaration. That can cause the agent to invoke this skill on incidental mentions of Findymail rather than explicit user intent, increasing the chance of unnecessary external queries, unintended data access, or surprising behavior.

Static analysis

No suspicious patterns detected.