Back to skill

Security audit

wxb-assistant

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Wangxiaobao business-data assistant, but it needs review because it persists and prints bearer tokens and exposes sensitive write/control actions without clear confirmation boundaries.

Review this before installing. Use it only on a trusted machine with a least-privileged Wangxiaobao account, avoid running authorization or data queries in shared terminals or logged automation, and clear ~/.wxb-auth-token when finished. Treat requests that edit recordings, switch tenants/projects, start or stop visits, submit tables, add comments, or delete/ignore records as sensitive actions that should require explicit confirmation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/auth-manager.js:156
Finding

Authentication Token Stored in Plaintext with Non-Atomic Permission Hardening

Content
View full analysis

Vulnerability Details

File Location: scripts/auth-manager.js:156-168
Vulnerability Type: Plaintext credential storage and insecure file creation
Risk Level: High

Vulnerable Code

js
saveToken(token) {
  try {
    fs.writeFileSync(this.tokenPath, token, 'utf-8')
    try {
      fs.chmodSync(this.tokenPath, 0o600)
    } catch (e) {
      // Permission hardening failure is ignored.
    }
  } catch (e) {
    throw e
  }
}

Technical Analysis

The application persistently stores the authentication bearer token as plaintext in ~/.wxb-auth-token. File permissions are restricted only after the file has already been created or overwritten. Initial access permissions therefore depend on the process umask, creating a window in which the token may be accessible more broadly than intended.

In addition, a failure to apply mode 0600 is ignored, allowing execution to continue while the credential file may retain insecure permissions. The token is not encrypted, expiration-validated, rotated, or protected through an operating-system credential store.

Attack Path

  1. A user completes the documented QR-code authorization process.
  2. The application receives an authenticated bearer token.
  3. saveToken() writes the complete token to ~/.wxb-auth-token as plaintext.
  4. The file is initially created according to the current process umask.
  5. Permission hardening may fail without stopping authorization.
  6. Another local process or account with access to the file copies the token.
  7. The attacker supplies the stolen token in the X-Auth-Token header when calling the Wangxiaobao API.

Impact Assessment

Successful exploitation exposes the authenticated user's session privileges. The token may permit access to sensitive customer profiles, recordings, transcripts, visits, tenant and project information, sales analysis, and other data available to the account. It may also authori ...[truncated 354 chars]

Remediation
View remediation

Remediation Suggestions

  1. Store the token in an operating-system credential manager instead of a plaintext file.
  2. If file storage is unavoidable, create the file atomically with restrictive permissions from the outset, such as by using fs.openSync(path, 'w', 0o600) followed by a controlled write.
  3. Fail closed if secure permissions cannot be established; do not silently ignore permission errors.
  4. Write to a securely created temporary file and atomically rename it to prevent partially written credentials.
  5. Encrypt the token at rest using a key protected outside the token file.
  6. Validate token expiration before reuse and implement revocation and rotation.
  7. Avoid indefinite retention and automatically delete expired credentials.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/auth-manager.js:197
Finding

Authentication Token Disclosed Through Standard Output

Content
View full analysis

Vulnerability Details

File Location: scripts/auth-manager.js:197-200 and scripts/auth-manager.js:207-208
Vulnerability Type: Sensitive credential exposure through process output
Risk Level: High

Vulnerable Code

js
const token = manager.getSavedToken()
if (token) {
  console.log(token)
}
js
.then(token => {
  console.log(token)
})

Technical Analysis

Both the authorization completion path and the check command print the complete bearer token to standard output. Standard output is frequently captured by Agent tool transcripts, terminal logging, CI systems, process supervisors, shell redirection, and observability platforms.

A bearer token does not require additional proof of possession. Anyone who obtains the printed value can attempt to replay it directly against the API until it expires or is revoked. Printing the token is unnecessary for checking authorization status and materially expands the credential's exposure surface.

Attack Path

  1. The user has an existing saved token or completes the authorization flow.
  2. An attacker, untrusted instruction, or ordinary operator invokes node scripts/auth-manager.js check or the default authorization command.
  3. The script prints the complete token to standard output.
  4. An Agent transcript, CI log, terminal capture, redirected file, or monitoring service retains the output.
  5. A party with access to that output extracts the token.
  6. The token is replayed in the X-Auth-Token header against wangkeapp.wangxiaobao.com.

Impact Assessment

Token disclosure can result in account-session compromise within the authorization scope of the affected user. An attacker may gain access to customer records, customer profiles, recordings and transcripts, visit details, tenant information, sales analysis, and other protected Wangxiaobao data. State-changing API operations exposed to the account may also become available. ...[truncated 189 chars]

Remediation
View remediation

Remediation Suggestions

  1. Never print the complete authentication token to standard output or standard error.
  2. Change the check command to return only an authorization status and an appropriate exit code.
  3. After authorization, print only a success message.
  4. If token identification is operationally necessary, display a non-reversible fingerprint or a heavily redacted value.
  5. Review and purge existing Agent transcripts, CI logs, terminal captures, and monitoring records that may contain previously printed tokens.
  6. Revoke and rotate tokens that may already have been logged.
  7. Add automated tests and secret-scanning rules that reject logging of token variables or authentication headers.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (36)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

Beyond business-data querying, the skill includes a remote QR-based authorization flow, local token persistence, and local auth-management actions. Hidden credential handling is especially sensitive because it introduces authentication and local secret-storage behavior that users may not expect from a simple query assistant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Beyond business-data querying, the skill includes a remote QR-based authorization flow, local token persistence, and local auth-management actions. Hidden credential handling is especially sensitive because it introduces authentication and local secret-storage behavior that users may not expect from a simple query assistant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

Beyond business-data querying, the skill includes a remote QR-based authorization flow, local token persistence, and local auth-management actions. Hidden credential handling is especially sensitive because it introduces authentication and local secret-storage behavior that users may not expect from a simple query assistant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Beyond business-data querying, the skill includes a remote QR-based authorization flow, local token persistence, and local auth-management actions. Hidden credential handling is especially sensitive because it introduces authentication and local secret-storage behavior that users may not expect from a simple query assistant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Beyond business-data querying, the skill includes a remote QR-based authorization flow, local token persistence, and local auth-management actions. Hidden credential handling is especially sensitive because it introduces authentication and local secret-storage behavior that users may not expect from a simple query assistant.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
- `customer-api.js` - 客户中心相关接口

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
- `other-api.js` - 其他功能(今日代办等)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The skill instructs or offers to execute a shell deletion command against a file in the user's home directory. Even though the target path is specific, allowing a natural-language-triggered skill to perform shell-based local file deletion is dangerous because it normalizes destructive local actions and can be abused or expanded if path handling changes.

Content

Scanner excerpt · SKILL.md (reported line 250)May include surrounding context.

如果需要重新授权或更换账号,可以删除授权文件:

bash
rm ~/.wxb-auth-token

或告诉我"清除授权",我会帮你处理。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is described as a data-query assistant, but this client exposes multiple state-changing operations such as editing audio, binding/unbinding visits, sharing audio, adding commentary, and submitting AI summaries. That mismatch expands the skill’s effective privilege surface and can enable unauthorized modification, sharing, or workflow actions if the agent invokes these methods based on ambiguous or malicious prompts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata frames this capability as a data-query assistant for recordings, visits, and customer insights, but this client also exposes many state-changing operations such as starting/stopping recordings, ending visits, ignoring records, and batch analysis. In an agent setting, that mismatch can cause overbroad invocation or accidental execution of destructive or privacy-impacting actions when the user only expects read-only access.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents shell/file behavior such as storing tokens under ~/.wxb-auth-token and deleting that file, but it does not declare any explicit tool scope or allowed-tools boundaries. That creates an unnecessary trust gap: a skill presented as a data-query helper can invoke filesystem or shell-capable behavior without a clearly constrained permission model.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger terms are broad and include generic phrases like customer data, recording, and sales analysis, which can cause the skill to activate in situations where the user did not intend to access or persist sensitive Wangxiaobao data. Over-broad triggering is more dangerous here because the skill handles customer information and credentials, not harmless reference data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill handles sensitive customer records and stores authorization tokens locally, yet the description does not provide a clear privacy/security warning before describing the flow. This increases the chance that users consent without understanding local secret storage, data sensitivity, retention, or the scope of access granted.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill positioning suggests quick data retrieval, but the documented feature set includes multiple state-changing management actions. This inconsistency can cause unsafe invocation patterns, especially if orchestrating agents route requests assuming the skill is informational only.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Visit-management operations such as starting/ending reception and controlling recording alter real business state, yet the surrounding description emphasizes querying data. In this context, hidden operational authority is more dangerous because users may invoke it casually while handling sensitive customer interactions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Tenant and project switching affects authorization context and what customer data becomes visible or mutable, but these capabilities are bundled into a query-oriented customer/panke skill. Context-switching features are sensitive because they can lead to cross-project confusion, accidental data exposure, or unintended writes in the wrong tenant.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON file defines the skill's natural-language inputs and descriptions exclusively in Chinese, which implicitly constrains usage to a specific language. Under the policy, forcing a language without opt-in or documented locale justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The package description is entirely in Chinese and presents the assistant as Chinese-language by default, with no indication of user language choice or a documented region-specific constraint. This may violate language/locale policy if the skill is expected to support user preference rather than implicitly forcing one locale.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill manifest describes a query-oriented assistant for looking up 旺小宝 data, but this client exposes state-changing operations such as switching tenant/project context. In an agent setting, hidden context-switch capabilities can cause cross-tenant data access or actions in the wrong project if the model invokes them without explicit user understanding or authorization.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file exposes write and mutation capabilities for 盘客 tables, comments, audio edits, binding/unbinding, and workflow actions even though the skill is presented as primarily read/query functionality. In an LLM-driven tool, undocumented write paths materially increase risk of unauthorized data modification, workflow tampering, or accidental corruption of customer and recording-related records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI directly prints user, customer, visit, recording, and related business data to stdout without masking, minimization, or warning. In shared terminals, logs, CI systems, agent transcripts, or observability pipelines, this can leak sensitive personal or operational information beyond the intended audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs HTTPS API calls and automatically attaches an authentication token in the X-Auth-Token header, while many methods send or retrieve recording, transcript, video, and commentary data. Although the code has developer comments, it contains no user-facing confirmation, warning, or disclosure that sensitive data and credentials will be transmitted to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code performs multiple HTTPS requests that send customer-related query parameters and request bodies to backend endpoints, including customer details, trajectory, recordings, and operation logs. The file contains internal comments about functionality, but no confirmation prompt, user-facing log, or warning that user/customer data will be transmitted to external services.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill manifest describes a query-oriented assistant for viewing customer, recording, and analysis data, but this client also exposes write-side operations such as re-prediction and user operation logging. That mismatch increases the risk that an agent can trigger state-changing actions the user did not expect, potentially altering backend data, initiating processing, or generating audit events without clear consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is described as a query/read-oriented assistant for accessing recordings, visits, customer profiles, and analysis data, but this API client also exposes a state-changing operation to ignore a visit record. That creates a capability mismatch: an agent or prompt path intended only for retrieval could invoke a write action that alters business workflow or suppresses follow-up, which is risky in a sales/customer-management context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.