Security audit
Crisp
Security checks for vulnerabilities and agentic risk
Overview
This Crisp skill is a coherent OOMOL connector wrapper with disclosed read access and one confirmed write action for sending support messages.
Install this only if you intend to let OOMOL mediate access to your Crisp account. Reads can expose customer conversations and messages, and `send_text_message` can post operator replies, so confirm message targets and payloads carefully before allowing write actions.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
