Back to skill

Security audit

Microsoft Text Translate

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Microsoft Text Translate connector wrapper with no hidden code, persistence, or unrelated data access in the artifact.

Before installing, confirm you are comfortable sending translation inputs through OOMOL's Microsoft Text Translate connector and using the OOMOL CLI/account setup. Avoid using it for sensitive text unless that data is appropriate for the connected Microsoft/OOMOL service.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The description says to use this skill for ANY Microsoft Text Translate request, including broad 'searching and reading data' phrasing, which can cause the agent to invoke this skill in cases where a direct answer or a more appropriate tool would suffice. Over-broad routing increases the chance of unintended external calls, unnecessary data disclosure to a third-party connector, and reduced user control over when translations are sent off-platform.

Static analysis

No suspicious patterns detected.