Back to skill

Security audit

Help Scout Docs

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed read-only Help Scout Docs connector that uses OOMOL, with no evidence of hidden or destructive behavior.

Install this only if you want an agent to read and search Help Scout Docs through your OOMOL-connected account. Confirm you trust OOMOL with the Help Scout connection, and treat CLI installation, login, billing, or account-connection steps as user-approved setup actions rather than routine automatic behavior.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description uses an overly broad directive ('Use this skill for ANY Help Scout Docs request'), which can cause an agent to route all Help Scout Docs-related tasks through this skill without sufficient task-level validation. While this skill appears read-only in practice, the broad trigger weakens least-privilege tool selection and could become dangerous if the connector later adds write or destructive actions, or if sensitive data access should be constrained.

Static analysis

No suspicious patterns detected.