Back to skill

Security audit

Starton

Security checks for vulnerabilities and agentic risk

Overview

This Starton skill is a disclosed service connector with scoped `oo` CLI access and explicit confirmation rules for write and destructive actions.

Install only if you trust OOMOL to broker your Starton connection and you are comfortable letting the agent manage Starton IPFS pins through the `oo` CLI. Confirm the exact target before deletion, and also ask for confirmation before `pin_existing_file` because it creates a pin even though the artifact does not tag it as `[write]`.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger text says to use this skill for ANY Starton request, including reading, creating, updating, and deleting data. That broad routing instruction can cause the agent to invoke this skill for all Starton-related tasks, increasing the chance of unintended write or destructive operations being selected when a narrower, safer path would be preferable.

Static analysis

No suspicious patterns detected.