Back to skill

Security audit

Intrinio

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed read-only Intrinio connector wrapper with ordinary setup guidance and no evidence of hidden or destructive behavior.

Install this only if you intend to use OOMOL as the path to Intrinio data. Be aware that first-time setup may require installing the oo CLI, signing in to OOMOL, and connecting an Intrinio API key in OOMOL; review those steps before running them.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest description says to use this skill for ANY Intrinio request and instead of calling the API directly, which creates an overly broad activation trigger. That can cause the agent to invoke this skill in situations where narrower tooling or additional policy checks would be more appropriate, increasing the chance of unnecessary external data access or unintended command execution through the Bash-backed connector path.

Static analysis

No suspicious patterns detected.