Back to skill

Security audit

Just One API

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a read-oriented Just One API connector, but its setup instructions can execute a remote installer script without verification.

Review before installing. The normal connector actions appear intended for reading/searching Just One API data, but do not let an agent run the CLI installer automatically unless you trust OOMOL's installer source and are comfortable executing remote setup code on your machine.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install software with curl ... | bash, which downloads and executes a remote script without prior verification, pinning, or integrity checking. If the hosting server, network path, or install script is compromised, this becomes an immediate arbitrary code execution path on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 316)May include surrounding context.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest markets the skill as being for 'searching and reading data', but it authorizes generic Bash execution via allowed-tools: [Bash(oo *)], which delegates trust to an external CLI and its subcommands rather than to a narrowly scoped read-only interface. In context, this mismatch can cause users or downstream agents to treat the skill as safer than it is, especially since the document also anticipates state-changing actions, creating a least-privilege and capability-transparency problem.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation says state-changing actions will be tagged [write] or [destructive], but no such tags appear in the action inventory, so users cannot reliably identify risky operations from the list itself. This weakens safety review and could lead an agent to invoke a mutating action without appropriate confirmation because the promised labeling mechanism is absent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.