Back to skill

Security audit

wxb-assistant

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real Wangxiaobao assistant, but it gives broad access to sensitive customer and recording systems and includes write/control actions that need manual review.

Install only if you trust the publisher and intend the assistant to use your Wangxiaobao account for broad customer, recording, tenant, visit, and analytics access. Use it on a private machine, avoid shared terminals or logs, clear ~/.wxb-auth-token when finished or changing accounts, and manually confirm any tenant switch, share, delete, bind, comment, submit, update, or recording/reception control action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (22)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill advertises substantial capabilities that imply shell/environment access and local file handling, yet it declares no explicit permissions. This creates a transparency and consent problem: a caller may invoke a seemingly harmless data-query skill without realizing it can persist credentials locally and run host-level actions. In a skill that handles authentication tokens and account-linked business data, undeclared capabilities materially increase risk.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
The documented behavior goes far beyond passive querying and includes authentication capture/storage, project and tenant switching, state-changing remote actions, and operational controls. This mismatch is dangerous because users and calling systems may trust the skill as read-only while it can alter data, affect workflows, and act under the user's account context. The broad scope also increases the blast radius if the skill is triggered unintentionally.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
Although presented as a data assistant, the skill includes many state-changing operations such as editing records, binding/unbinding entities, starting or ending visits/recordings, creating tasks, and updating intent levels. In this context, the mismatch makes accidental misuse more likely because natural-language requests for '查看' or analysis may invoke actions that modify remote business systems or customer records. That is especially sensitive given the CRM-like nature of the data involved.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The evals exercise user introspection, tenant enumeration, and tenant switching operations that go beyond the manifest's stated read-oriented scope of querying recordings, visits, customer profiles, and related analytics. In a multi-tenant data system, exposing or normalizing tenant discovery and context switching without explicit authorization and user-intent safeguards can enable unintended access expansion or cross-tenant data exposure if the downstream tool enforces permissions weakly.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The `rePredict` eval introduces a state-changing operation in a skill described primarily as a data-query assistant. Hidden write actions are dangerous because a user may reasonably expect read-only behavior, while the action can trigger model recomputation, alter system state, consume resources, or affect downstream business workflows without sufficiently informed consent.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill manifest describes a query-oriented assistant for viewing 旺小宝 data, but the code exposes state-changing session operations such as switching tenant and project. In an agent setting, hidden context-switching can redirect subsequent reads into a different tenant/project scope and cause unintended access or actions against the wrong organizational data boundary.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
This file exposes numerous write-capable operations—editing recordings, binding/unbinding audio, submitting summaries, adding commentary, editing/submitting 盘客 tables, accepting golden content, and updating sales intent—despite the skill being presented as a data query tool. In an LLM-agent context, this creates a privilege/scope mismatch where a user or prompt that appears to request inspection could trigger irreversible modifications to sensitive business records.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill metadata describes a query-oriented assistant for viewing recordings, customer profiles, and analytics, but this API client also exposes state-changing operations such as edit, bind/unbind, comment submission, share, and apply/submit actions. Expanding privileges beyond the declared read-oriented scope increases the blast radius of prompt abuse or accidental invocation, enabling unauthorized business record changes through a tool users may trust as read-only.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The shareAudio capability allows external dissemination of recording data, which is especially sensitive given the skill handles recordings, transcripts, and customer-related information. In a skill framed as a fast query assistant, hidden sharing functionality creates a serious risk of data exfiltration if the agent is misprompted, compromised, or used without the user's clear understanding.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Write operations such as editAudio, bindVisit, unbindAudios, addCommentary, submitSummaryAndQa, and applyVideo allow creation or modification of business records in a tool presented as a data lookup assistant. This mismatch makes the skill more dangerous because operators may invoke it assuming read-only behavior, while an attacker could use prompt injection or confused-deputy flows to alter records or trigger workflows.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is described as a query-focused assistant for viewing recordings, visits, customer profiles, and analysis, but this method exposes a state-changing action to ignore a visit record. That creates a privilege/scope mismatch: an agent or prompt path intended only for read access could suppress or alter operational records, which may hide tasks or affect business workflows if invoked improperly.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is presented as a read/query assistant, but this client exposes state-changing operations such as submitting/editing tables, marking visits, accepting content, updating intent, adding comments, and deleting focus items. In an agent setting, that mismatch can let normal-looking user prompts trigger unauthorized modification or deletion of customer-related records, especially if higher-level guardrails assume the skill is read-only based on its description.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The skill metadata describes a query-oriented assistant for looking up recordings, visits, customer profiles, and analytics, but this client also exposes state-changing operations such as starting/stopping recordings, ending visits, ignoring visits, rebinding audio, and batch analysis. That expands the skill from read-only data access into operational control of business processes and recording workflows, creating a clear capability mismatch that could be abused if the agent invokes these methods unexpectedly or under prompt manipulation.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The skill is presented as a business-data lookup tool, yet it includes device and Wi‑Fi status endpoints that reach into operational/hardware context. Even if these are legitimate backend APIs, exposing them through a broader query assistant increases unnecessary privilege and information exposure, which could aid reconnaissance or trigger unintended management actions in a sensitive enterprise environment.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The module documentation states it is a badge-visit API client, but the implementation also supports virtual visit management, recording control, audio binding, and other operational actions. This kind of misleading documentation is dangerous because reviewers, integrators, and policy systems may assume a narrower read-only scope than the code actually has, increasing the chance that overprivileged functionality ships unnoticed.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation conditions are very broad, covering common terms like recording, visit, customer profile, and sales analysis. This increases the chance of over-triggering in unrelated or ambiguous conversations, which is risky because the skill can access sensitive business/customer data and perform more than simple retrieval. Overbroad invocation is more dangerous here than in a harmless reference skill because it is tied to authenticated enterprise data access.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill stores a persistent authorization token in a predictable local path and does not clearly communicate the account-access, privacy, and persistence implications to the user. A locally stored bearer token can grant ongoing access to recordings, customer profiles, and operational functions if the host is compromised, shared, or insufficiently protected. The sensitivity is elevated because the token appears to authorize both data access and remote modifications.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation presents mutating operations alongside query operations without clearly warning that they can change remote system state. Users may reasonably assume the skill is informational, yet actions like editing recordings or re-analysis can alter records or trigger backend processing under their account. In a business workflow system, unclear disclosure can lead to unintended changes and accountability issues.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The evals rely on broad natural-language triggers such as showing customer lists, viewing recordings, or checking customer profiles, but they do not document scope restrictions, identity checks, or consent boundaries for potentially sensitive customer data. In a CRM-style skill handling recordings and customer analytics, ambiguous queries can cause overbroad retrieval of personal or commercially sensitive information if the agent maps casual language directly to privileged backend actions.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The CLI prints raw customer, visit, tenant, and audio-related responses directly to stdout, which can expose sensitive business and personal data in terminal history, shell logs, CI logs, or monitoring collectors. Because this skill handles customer profiles, visit records, and audio/transcript data, the context makes indiscriminate console output more dangerous than in a non-sensitive utility.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The client exposes sensitive operational actions like starting and stopping visit audio recording through simple method calls with no built-in confirmation, safety interlocks, or indication that these actions affect real-world recording state. In the context of an agent skill, that makes prompt-induced or mistaken invocation more dangerous because it can alter recordings and visit workflows without explicit user intent.

Tool Parameter Abuse

High
Category
Tool Misuse
Content
如果需要重新授权或更换账号,可以删除授权文件:

```bash
rm ~/.wxb-auth-token
```

或告诉我"清除授权",我会帮你处理。
Confidence
92% confidence
Finding
rm ~/

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.