Back to skill

Security audit

TabAPI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward TabAPI connector wrapper with disclosed setup steps and no evidence of hidden or destructive behavior.

Before installing, be aware that this skill can send requested public URL, domain, search, and lookup payloads to TabAPI through your OOMOL-connected account, and first-time setup may install and authenticate the oo CLI if it is not already configured.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.