Back to skill

Security audit

GetResponse

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed GetResponse connector that can read, create, update, and delete account data, with explicit confirmation required for state-changing actions.

Install only if you want your agent to operate your GetResponse account through OOMOL. Review write and delete requests carefully, especially permanent contact deletion, and only approve payloads you understand.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description is extremely broad: it instructs the agent to use this skill for ANY GetResponse request and whenever a task merely involves GetResponse. This can cause over-selection of the skill in ambiguous contexts, leading the agent to invoke a connector with account-backed credentials for tasks the user did not clearly intend, including write or destructive operations if later prompted.

Static analysis

No suspicious patterns detected.