Back to skill

Security audit

TianAPI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed OOMOL connector for read-only TianAPI queries, with one setup command that users should verify before running.

Install only if you intend to use TianAPI through an OOMOL-connected account. Before running the oo CLI installer commands, verify they come from the official OOMOL source, and remember that TianAPI requests may consume API quota or credits.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill includes a one-line installer that downloads a remote script and pipes it directly to bash, which creates a supply-chain and arbitrary code execution risk if the remote host, script, transport, or distribution path is compromised. Because this is embedded in agent instructions, an automated system or user may execute it without independently verifying integrity, amplifying the danger.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use this skill for "ANY TianAPI request" and "Whenever a task involves TianAPI," which is an extremely broad trigger without scope boundaries or exclusion examples. In a manifest file, this can overlap with many ordinary tasks that merely mention TianAPI, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Lines L64-L66 document behavior for write and destructive actions, yet the available action list in L40-L60 contains only get_, list_, query_, and search_ operations and no actions are actually tagged [write] or [destructive]. This creates an intent/documentation mismatch by implying the skill may perform state-changing TianAPI operations when the documented implementation is read-only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.