jeo-skill
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHPERSISTENCECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PERSISTENCE]: The undocumented script
scripts/repair-codex-omc-posttool-hooks.shmodifies internal JavaScript files within the hidden~/.codex/plugins/cache/omc/directory. These files belong to a third-party application ('oh-my-claudecode'). By programmatically altering these executable hooks to remove output suppression features, the skill performs an unauthorized lateral modification of the host environment's toolchain that persists across sessions. - [COMMAND_EXECUTION]: The
jeo-skill.pyscript utilizessubprocess.run()to execute shell commands, specifically invokingnpxto install additional software. While this is part of the skill's stated purpose, it provides a vector for downloading and executing code from remote sources. - [EXTERNAL_DOWNLOADS]: The skill performs runtime network requests to
raw.githubusercontent.comto fetch a skill catalog, making the tool's behavior dependent on external content from an untrusted account. - [OBFUSCATION]: The
repair-codex-omc-posttool-hooks.shscript encapsulates complex logic within a Python heredoc inside a shell script. This pattern can be used to hide the complexity and true intent of file system modifications from basic text-based security scanners. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from a remote JSON catalog and uses it to populate descriptions and tags that an agent processes. The lack of content sanitization for these fields provides an attack surface for indirect prompt injection. Evidence: Ingestion Point:
download_catalog()injeo-skill.py; Boundary Markers: Absent; Capability Inventory:subprocess.run(npx),os.symlink,os.replace; Sanitization: Structural validation only.
Recommendations
- AI detected serious security threats
Audit Metadata