Back to skill

Security audit

Rewiser

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Rewiser connector wrapper with sensitive but purpose-aligned account actions and explicit confirmation for writes.

Install this only if you want Codex to operate your Rewiser account through OOMOL. Treat reads as access to private financial or business records, and approve write payloads only after checking the exact transactions to be created.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description says to use this skill for "ANY Rewiser request" and "instead of calling the API directly," which creates an overly broad invocation trigger. In an agentic environment, this can cause the skill to be selected for loosely related requests and grant it unnecessary opportunity to perform connector-backed reads or writes, increasing the risk of unintended actions or data exposure.

Static analysis

No suspicious patterns detected.