Back to skill

Security audit

Firstbase

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Firstbase read-only connector through OOMOL, with no artifact evidence of hidden, destructive, or unrelated behavior.

Install this only if you want Codex to read Firstbase account data through OOMOL's oo CLI. Confirm your OOMOL and Firstbase connection is intentional, and be aware that future connector actions marked write or destructive should require explicit confirmation before use.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The phrase 'Use this skill for ANY Firstbase request' creates an overly broad invocation scope that can cause an agent to select this skill in situations where direct API use, a narrower skill, or additional user confirmation would be more appropriate. In an agentic environment, ambiguous universal routing language increases the chance of unintended tool execution and bypasses more precise task-to-tool matching controls.

Static analysis

No suspicious patterns detected.