Back to skill

Security audit

YoPlanning

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed read-only YoPlanning connector that uses OOMOL's CLI and does not show hidden, destructive, or unrelated behavior.

Install this only if you want an agent to read YoPlanning data available to your connected OOMOL account. Review the OOMOL CLI install and account connection steps, and avoid using it for write-like YoPlanning requests unless the exact action and payload are explicitly confirmed.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger text instructs the agent to use this skill for ANY YoPlanning-related request, which is broader than necessary and can cause unintended invocation even when a direct answer, another safer skill, or explicit user confirmation would be more appropriate. In agent frameworks, overly broad routing increases the chance of unnecessary tool execution and expands the operational surface exposed to user prompts.

Static analysis

No suspicious patterns detected.