Back to skill

Security audit

Workpath

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly scoped Workpath read-only connector that uses OOMOL's oo CLI and does not show hidden, destructive, or unrelated behavior.

Before installing, confirm you are comfortable allowing the agent to read Workpath goals, key results, teams, and users visible to your connected OOMOL account. Do not run the setup or installer steps unless the oo CLI or account connection is actually missing.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The phrase 'Use this skill for ANY Workpath request' is an overly broad routing instruction that can cause the agent to invoke the skill for all Workpath-related tasks without first evaluating whether the request is appropriate, least-privileged, or better handled by another mechanism. In an agent ecosystem, this kind of unconditional delegation increases the risk of overreach, accidental data exposure, and unsafe execution paths because it suppresses normal tool-selection scrutiny.

Static analysis

No suspicious patterns detected.