Back to skill

Security audit

LoyJoy

Security checks for vulnerabilities and agentic risk

Overview

This skill provides a clearly disclosed OOMOL CLI wrapper for LoyJoy account actions, with write actions identified and user confirmation required.

Install only if you intend to let Codex operate your LoyJoy tenant through OOMOL. Review write payloads before approval, and be aware that search/list/get actions may expose tenant knowledge base or process data available to your connected account.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.