Security audit
OrcaRouter
Security checks for vulnerabilities and agentic risk
Overview
This skill is a coherent OrcaRouter connector that uses the OOMOL oo CLI with disclosed setup, account connection, and confirmation rules for write actions.
Install this only if you intend to let the agent use your connected OOMOL/OrcaRouter account. Review write payloads before approving them, since completions, messages, or embeddings may send user-provided content to OrcaRouter and may incur account usage or billing.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
