Back to skill

Security audit

Paradym

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Paradym connector skill that can read and create Paradym workflow objects, with clear confirmation guidance for writes.

Install this only if you want an agent to operate your Paradym account through OOMOL. Review the exact payload before approving write actions such as credential offers or verification requests, and only complete the one-time oo CLI/OOMOL connection setup from sources you trust.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger text instructs the agent to route any Paradym-related task through this skill, which is broader than necessary and can override more context-appropriate handling. Because this skill supports both read and write operations, an overly broad trigger increases the chance of invoking state-changing connector actions in situations where a narrower tool or additional policy checks should apply.

Static analysis

No suspicious patterns detected.