Back to skill

Security audit

xiaodu-leave-home-mode-official

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real leave-home automation skill, but it needs review because short everyday phrases can trigger smart-home changes, personal schedule summaries, and remembered security preferences.

Install only if you are comfortable with a voice-triggered leave-home routine that can shut off household devices, query and speak schedule/reminder information, and remember future preferences. Review or disable automatic lock preferences, use explicit trigger phrases where possible, and keep preference files inspectable and deletable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation phrases include common, natural utterances such as “出门了” and “帮我把家里设备关一下”, which can be spoken casually or in ambiguous contexts. Because this skill can trigger home automation actions and query personal summary information, broad activation increases the risk of unintended invocation, causing device state changes and privacy exposure without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description emphasizes convenience and safety checks but does not clearly warn users that it may access and summarize personal calendar, memo, and reminder data. In this context, the skill explicitly instructs runtime calls that retrieve and speak such information, so insufficient disclosure can lead to privacy surprises, accidental disclosure to nearby people, and consent issues.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase '出门了' is common everyday speech and can naturally occur in casual conversation, but this skill maps it to home-control actions. Because the skill can shut down devices and potentially proceed into security-relevant flows, broad activation phrases increase the risk of accidental or out-of-context invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The alternate trigger '离家模式' is also ambiguous and may be spoken in discussion rather than as a command, yet it initiates automation behavior. In a skill that controls household devices, weakly constrained phrases can cause unintended shutdown routines and confusing side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill reads weather, calendar, and reminders as part of the leave-home routine, but calendar and reminder data are privacy-sensitive and the test cases do not indicate any warning, permission explanation, or minimization. This can expose personal schedule and task information through ambient voice output or unexpected access during a device-control flow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The test cases introduce a door-lock actuation flow ('需要帮你上锁吗?' -> execute locking) even though the skill is described primarily as a leave-home checklist and device shutoff orchestrator. Adding physical security control beyond the declared scope increases the chance of unintended lock operations, authorization gaps, or users not realizing the skill can control access to the home.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The test cases add persistence of user preferences into XIAODU_CONTEXT.md, creating a memory/storage capability that is not disclosed in the manifest. Undeclared persistence can store behavioral preferences such as lock and device-control defaults, raising privacy, transparency, and consent concerns and enabling future actions based on remembered settings the user may not expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The tests explicitly describe storing user preferences in XIAODU_CONTEXT.md without any notice about persistence, review, or deletion. Persisting automation preferences can silently change future physical-device behavior, especially for door-lock and device-scope defaults, making this more dangerous than ordinary cosmetic personalization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

All trigger phrases, prompts, confirmations, and example outputs are specified only in Chinese, including the required lock-confirmation phrasing. The file does not indicate that the skill is region-specific or that users can opt into Chinese, which creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases include very common everyday utterances such as '出门了', '我走了', and '关门关灯', which can plausibly be spoken in ordinary conversation and unintentionally activate a high-impact automation. In this skill’s context, unintended activation is more dangerous than usual because it can shut down home devices and initiate lock-related actions during a routine interaction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill treats weather, calendar, and reminder retrieval as part of the default flow without warning that privacy-sensitive personal data will be accessed and summarized aloud. In a leave-home scenario, this can expose schedules, reminders, or alarms to nearby people or activate when the user did not expect private data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions say user preferences expressed during the interaction should be written into XIAODU_CONTEXT.md, but do not tell users that behavioral preferences will be persisted. Those preferences can reveal occupancy habits, room usage, and security routines, creating a privacy risk beyond the immediate session.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Persisting free-form user preferences into a context file can accumulate sensitive behavioral and household security information, such as whether doors should lock automatically or which rooms are usually unoccupied. In this skill, that data is particularly sensitive because it maps directly to leave-home routines and home-device control behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
99% confidence
Finding

该小节标题写明“多设备必须确认”,但具体预期却是“按默认范围执行,不需要逐个确认”。这不是单纯信息缺失,而是文档标题与预期动作直接相互矛盾,可能误导实现者对用户确认策略的理解。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.