Back to skill

Security audit

Jamie

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Jamie connector skill that reads meeting-related data through OOMOL's oo CLI, with no evidence of hidden, destructive, or unrelated behavior.

Install this only if you want Codex to access Jamie meeting data through your OOMOL-connected account. Be aware that Jamie meeting transcripts, summaries, and tasks can contain sensitive information, and the skill is written to run read/search actions directly for Jamie-related requests.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger text is extremely broad: it directs the agent to use this skill for ANY Jamie-related request and to prefer the skill over direct API use. That can cause unintended invocation for loosely related prompts, expanding the situations where external data access occurs and increasing the chance of unnecessary data exposure or incorrect tool routing.

Static analysis

No suspicious patterns detected.