Back to skill

Security audit

SunoAPI

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed SunoAPI connector for OOMOL's CLI, with no hidden code, though users should review CLI setup and confirm credit-consuming actions.

Install only if you trust OOMOL, the `oo` CLI, and the connected SunoAPI account flow. Review the CLI installation command before running it, and confirm the exact payload and likely credit usage before approving any generation, upload, conversion, extension, or transformation action.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.