Back to skill

Security audit

Taiga

Security checks for vulnerabilities and agentic risk

Overview

This Taiga skill is a coherent OOMOL connector wrapper with disclosed read and write capabilities and explicit confirmation guidance for state-changing actions.

Install this only if you intend to let Codex use your connected OOMOL account to read and create or update Taiga records. Review write payloads before approval, and only run the one-time CLI install or auth setup if you trust OOMOL and need the connector.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description and frontmatter instruct the agent to use this skill for any Taiga-related request, creating an overly broad routing trigger. This can cause the skill to be invoked in situations where direct handling, narrower tooling, or stronger confirmation logic would be more appropriate, increasing the chance of unintended state-changing operations through a privileged connector.

Static analysis

No suspicious patterns detected.