Back to skill

Security audit

YouTube

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed YouTube connector that can read and modify a connected account, with explicit confirmation requirements for write and destructive actions.

Install only if you want Codex to operate a YouTube account through OOMOL. Review write and destructive requests carefully before approving them, especially uploads, public comments, metadata updates, and deletions. Treat the oo CLI install and OOMOL account connection as trusted third-party dependencies.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.