Back to skill

Security audit

Help Scout

Security checks for vulnerabilities and agentic risk

Overview

This Help Scout skill is a disclosed OOMOL connector for reading and updating Help Scout data, with write actions labeled and user confirmation required.

Install only if you intend to let Codex operate your Help Scout account through OOMOL. Review write payloads carefully before approval, especially replies, workflows, tag replacements, status changes, and custom-field replacements, because they can affect real customer-support records.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger phrase says to use this skill for ANY Help Scout request instead of calling the API directly, which is overly broad and can cause the agent to invoke this skill in situations where a narrower or safer path would be more appropriate. In a skill that supports both read and write operations against a live customer-support system, over-invocation increases the chance of unintended data access or state-changing actions being taken under the wrong context.

Static analysis

No suspicious patterns detected.