Back to skill

Security audit

Tushare

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Tushare connector wrapper that uses the OOMOL `oo` CLI for disclosed data-reading actions.

Install this if you want the agent to query Tushare through an OOMOL-connected account. Before first use, be aware that setup may require installing the `oo` CLI and signing into OOMOL; review those steps and the account connection before approving them.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description instructs the agent to use this skill for ANY Tushare request and whenever a task involves Tushare, without narrowing scope to specific data-access patterns or requiring user intent validation. This can cause over-selection of the skill and automatic execution of Bash-based connector commands in situations where a direct answer, clarification, or safer alternative would be more appropriate.

Static analysis

No suspicious patterns detected.