Back to skill

Security audit

Chorus

Security checks across malware telemetry and agentic risk

Overview

This skill coherently provides read-only Chorus access through the OOMOL CLI, with no artifact-backed evidence of hidden, destructive, or exfiltrating behavior.

Install this if you want an agent to read Chorus data through your OOMOL connection. Be aware it can access Chorus conversations and business records visible to the connected account, and setup may require installing/signing into the oo CLI and connecting Chorus in OOMOL.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description instructs the agent to use this skill for ANY Chorus request, creating an unnecessarily broad activation scope. While the skill only exposes read-oriented Chorus actions in this file, the trigger language can cause the agent to route all Chorus-related tasks through this skill without checking whether the request is appropriate, least-privileged, or within the user's intended scope.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.