Back to skill

Security audit

Xingpan API

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Xingpan API connector, but its fallback setup tells the agent to execute a remote installer script without integrity checks or clear user approval.

Review this before installing if the oo CLI is not already present. Normal Xingpan API calls are narrowly described, but do not let an agent run the provided remote installer automatically; install oo from trusted official instructions with verification or approve the exact install step yourself.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into a shell, which bypasses integrity verification and executes whatever content the remote server returns at runtime. In a skill context, this is especially dangerous because the skill is operational guidance for an automated agent, increasing the chance of unreviewed code execution if the CLI is missing.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

Static analysis

No suspicious patterns detected.