Back to skill

Security audit

Jin10

Security checks for vulnerabilities and agentic risk

Overview

This Jin10 connector skill is mostly purpose-aligned, but its first-time setup tells users to execute remote installer scripts directly without verification.

Review this before installing. The Jin10 actions themselves appear scoped to reading connector data, but do not run the documented curl | bash or irm | iex setup commands unless you trust OOMOL's installer source and have checked the official installation path, version, and integrity yourself. Prefer a pinned or package-manager installation method when available.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:58
Finding

Unverified Remote Installers Are Downloaded and Executed Directly

Content
View full analysis
): ```bash curl -fsSL https://cli.oomol.com/install.sh | bash # macOS / Linux ``` ```powershell irm https://cli.oomol.com/install.ps1 | iex # Windows PowerShell ``` ``` ### Technical Analysis The installation instructions retrieve mutable scripts from `cli.oomol.com` and immediately execute them with Bash or PowerShell. The scripts are not included in the audited project, so their effective behavior cannot be reviewed from the repository and may change after this audit. Although installing the `oo` CLI is relevant when the required tool is absent, direct `curl | bash` and `irm | iex` execution is not the minimum safe installation mechanism. The instructions do not pin a release, validate a cryptographic signature or checksum, present the downloaded content for inspection, or require explicit approval immediately before execution. Using HTTPS protects data in transit under ordinary conditions, but it does not protect against compromise of the hosting service, release pipeline, account, or trusted endpoint. There is no evidence in the reviewed file that the current remote scripts are malicious; the vulnerability is that their future content is implicitly trusted and executed. ### Attack Path 1. The `oo` command is unavailable on the user's system. 2. The Agent or user follows the documented first-time setup instructions. 3. Bash or PowerShell downloads the current installer from `cli.oomol.com`. 4. The shell executes the response without first saving, inspecting, pinning, or cryptographically verifying it. 5. If the remote endpoint or its software-distribution pipeline has been compromised, attacker-controlled commands execute wit ...[truncated 1022 chars]
Remediation
View remediation
/install.sh" echo " oo-installer.sh" | sha256sum --check - less oo-installer.sh bash oo-installer.sh ``` The production instructions should use the vendor's actual immutable release URL and independently published signature or checksum. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into a shell, which is a classic supply-chain and remote code execution risk. If the install endpoint, transport, DNS, or upstream distribution is compromised, arbitrary code could run immediately on the host without review.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says to use this skill for "ANY Jin10 request" and whenever a task involves Jin10, which is an expansive activation condition without clear boundaries or exclusions. This can overlap with many ordinary requests that merely mention Jin10, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.