Back to skill

Security audit

SpyFu

Security checks for vulnerabilities and agentic risk

Overview

This SpyFu skill is a disclosed, purpose-aligned read-oriented connector wrapper with no hidden persistence or destructive behavior in the artifact.

Before installing, confirm you trust OOMOL's oo CLI and are comfortable connecting your SpyFu account through OOMOL. The skill can read SpyFu analytics and account usage data when requested, and first-time setup may require installing the oo CLI and signing in.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill’s trigger text is overly broad because it instructs the agent to use this skill for ANY SpyFu-related request without narrowing scope by task type, user intent, or data sensitivity. That can cause unintended invocation and automatic execution of external connector actions in situations where a narrower tool, additional review, or explicit user confirmation would be safer.

Static analysis

No suspicious patterns detected.