Back to skill

Security audit

KoboToolbox

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed KoboToolbox connector with read, write, export, and delete actions, and it requires confirmation before state-changing or destructive actions.

Install this only if you want your agent to operate KoboToolbox through OOMOL. Review prompts carefully before approving writes, deployments, exports, validation changes, or deletion of submissions, because those actions can change or remove real KoboToolbox data.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The manifest description says to use this skill for ANY KoboToolbox request and instead of calling the API directly, which is an overly broad routing trigger. This can cause the agent to invoke a high-privilege connector in situations where a narrower skill, safer read-only path, or direct user clarification would be more appropriate, increasing the chance of unintended data access or state-changing operations.

Static analysis

No suspicious patterns detected.