Security audit
MySkool
Security checks for vulnerabilities and agentic risk
Overview
This plugin clearly discloses that it lets an agent read and optionally post, delete, and send DMs through the user's MySkool-connected Skool account.
Install only if you trust MySkool with access to the Skool account connected to your API key. Keep write and DM scopes off unless needed, review any exact post/comment/delete/DM confirmation carefully, and avoid configuring a custom API base URL unless you trust that endpoint with the API key and message content.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
