Back to skill

Security audit

Breeze

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Breeze read-only connector skill that uses the OOMOL `oo` CLI and shows no hidden code, malware signal, persistence, or destructive behavior.

Install this only if you intend your agent to read Breeze data through your OOMOL connection. Be aware that the trigger wording is broad, so avoid using it for casual discussion of Breeze unless you want connector-backed access; review any CLI installation or account-connection step before approving it.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The instruction to use this skill for ANY Breeze request is an overly broad routing rule that can cause the agent to invoke the skill whenever Breeze is merely mentioned, rather than when the user explicitly intends connector-backed access. In a security context, broad triggers increase the chance of unintended access to connected account data and make prompt-injection or context-confusion attacks easier to turn into real tool use.

Static analysis

No suspicious patterns detected.