Back to skill

Security audit

Zenventory

Security checks for vulnerabilities and agentic risk

Overview

This Zenventory skill is a disclosed OOMOL connector integration with scoped commands and explicit confirmation requirements before changing inventory data.

Install this only if you want Codex to operate Zenventory through your OOMOL-connected account. Reads can run directly, while create and update actions should be reviewed for the exact item, payload, and effect before approval. If first-time setup is needed, review the oo CLI install and account-connection steps before proceeding.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description instructs the agent to use this skill for ANY Zenventory request, including reading, creating, and updating data, without narrowing when it is appropriate or adding decision boundaries. This can cause over-routing of all Zenventory-related tasks through a powerful integration, increasing the chance of unintended write operations, unnecessary exposure to connected-account actions, or bypass of more context-specific safeguards.

Static analysis

No suspicious patterns detected.