Back to skill

Security audit

Google Forms

Security checks for vulnerabilities and agentic risk

Overview

This Google Forms skill is clearly scoped to using the OOMOL oo CLI for Google Forms tasks and discloses its read and write capabilities.

Install this if you want an agent to manage Google Forms through OOMOL. Review write payloads before approval, because actions like creating forms, batch updating forms, and changing publish settings can alter real Google Forms data. Only run the oo CLI installer or login steps when you intentionally want to set up OOMOL access.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.