Back to skill

Security audit

Jina AI

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Jina AI connector wrapper with scoped `oo` CLI access and user-confirmation guidance for write actions.

Before installing, understand that prompts and documents sent for embeddings or reranking will go through the OOMOL Jina AI connector and may consume service credits. Confirm the payload before any write-tagged action, and only run the first-time installer or login steps when setup is actually missing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrase 'Use this skill for ANY Jina AI request' is overly broad and can cause the agent to invoke this skill for loosely related mentions rather than clear connector operations. In practice, this increases the chance of misrouting tasks, unnecessary tool use, and unintended execution paths involving authenticated external actions, especially because the skill supports both read and write-capable connector operations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.