Back to skill

Security audit

Tonghuashun Financial Data

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed connector wrapper for retrieving Tonghuashun financial data through OOMOL, with no evidence of hidden, destructive, or unrelated behavior.

Install only if you intend to use OOMOL's oo CLI and a connected Tonghuashun Financial Data account. Be aware that actions send requests through OOMOL and some export actions upload datasets to transit storage; review payloads for any future actions marked write or destructive before approving them.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description instructs the agent to use this skill for ANY Tonghuashun Financial Data request and instead of calling the API directly, which is an overly broad routing rule. This can cause the agent to invoke the skill for loosely related finance tasks without adequate relevance checks, increasing the chance of unnecessary external data access, unintended command execution through the Bash-backed tool path, or bypass of safer/more precise native handling.

Static analysis

No suspicious patterns detected.