Back to skill

Security audit

Twilio

Security checks for vulnerabilities and agentic risk

Overview

This Twilio skill is a clearly disclosed OOMOL connector for reading Twilio data and sending messages or calls with confirmation for write actions.

Install only if you want OOMOL-connected access to your Twilio account. Review the exact payload before approving outbound calls or SMS/MMS messages, since those can affect recipients and billing, and revoke the OOMOL/Twilio connection when no longer needed.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description says to use this skill for ANY Twilio request and instead of calling the API directly, which creates an overly broad routing trigger. That can cause the agent to invoke this skill for low-risk reads, high-risk writes, or edge-case Twilio tasks without sufficiently narrowing intent, increasing the chance of unintended actions or misuse of connected credentials.

Static analysis

No suspicious patterns detected.