Back to skill

Security audit

LaunchDarkly

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed LaunchDarkly administration skill that can make powerful account changes, but its authority is scoped to LaunchDarkly through the OOMOL connector and includes approval guidance for risky actions.

Install this only if you want an agent to manage LaunchDarkly through your OOMOL connection. Review payloads carefully before approving write actions, and require explicit confirmation for deletes, token resets, and token creation because those can affect production feature flags, access, or account configuration.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.