Back to skill

Security audit

Workast

Security checks for vulnerabilities and agentic risk

Overview

This Workast skill is a focused connector that discloses its read and write actions and requires user confirmation before changing Workast data.

Before installing, users should understand that this skill can read and modify Workast tasks through their connected OOMOL account. Confirm task creation, updates, or completion payloads carefully, and only run the first-time install or login steps if the oo CLI or connection is actually missing.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description says to use this skill for "ANY Workast request" and "instead of calling the API directly," which is an overly broad invocation trigger. That can cause the agent to route loosely related prompts into this skill unnecessarily, increasing the chance of unintended reads or write-capable operations being selected in contexts where a narrower tool or direct user clarification would be safer.

Static analysis

No suspicious patterns detected.