Back to skill

Security audit

Xiabb

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real macOS dictation app, but it needs Review because the install flow weakens macOS protections and the app stores spoken text in logs.

Review before installing. Prefer a signed, notarized release with published checksums over the source install command. Expect audio/text to be sent to Google Gemini, avoid dictating secrets or regulated data, restrict and rotate the Gemini API key, and check or clear ~/Library/Logs/XiaBB.log because transcripts may be stored there.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:49
Finding

Unpinned Remote Repository Is Downloaded and Immediately Executed

Content
View full analysis
Remediation
View remediation
``` 2. Publish SHA-256 checksums for release archives and require verification before opening them: ```bash shasum -a 256 XiaBB-v1.0.0-macOS-arm64.zip ``` 3. Sign releases with a verifiable maintainer key and distribute a Developer ID-signed, notarized macOS application. 4. Separate retrieval from execution. Do not combine `git clone`, directory changes, and script execution in one command. 5. Explain the installer's filesystem changes and permission requirements before asking users to execute it. 6. Add release provenance, such as GitHub artifact attestations or Sigstore signatures, and verify it during installation. ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
install.sh:160
Finding

Installer Recursively Removes macOS Quarantine Metadata

Content
View full analysis
/dev/null || true echo " [ok] Quarantine attribute removed" ``` ### Technical Analysis The installer recursively clears all extended attributes from the installed application using `xattr -cr`. This can remove `com.apple.quarantine` and other extended attributes, suppressing the macOS quarantine state used by Gatekeeper and related security checks. Removing quarantine is not necessary to compile source code or copy an application bundle. It weakens platform protections precisely when code has just been obtained from a mutable remote source. The command also clears all extended attributes rather than narrowly handling a documented, necessary attribute. The use of `|| true` suppresses errors, preventing the installation from alerting the user if this security-sensitive operation behaves unexpectedly. ### Attack Path 1. A user obtains the project or installer from an untrusted or compromised source. 2. The attacker-controlled source is compiled or copied into `/Applications/XiaBB.app`. 3. The installer executes `xattr -cr` against the entire application bundle. 4. Quarantine metadata and potentially other security-relevant extended attributes are removed. 5. The user opens the application with reduced Gatekeeper/quarantine scrutiny. 6. The application executes with the user's permissions and may subsequently request microphone and Accessibility access. ### Impact Assessment This issue does not independently grant administrative privileges, but it breaks a macOS defense-in-depth boundary and increases the reliability of executing altered or untrusted application code. Combined with the mutable remote installation path, it can facilitate arbitrary user-level code execution and social engineering for powerful ...[truncated 287 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
native/main.swift:827
Finding

Gemini API Key Is Embedded in a WebSocket URL Query Parameter

Content
View full analysis
`. 4. A diagnostic tool, local proxy, crash collector, endpoint monitor, or other component records the complete request URL. 5. A party with access to those records extracts the key. 6. The party reuses the key to make Gemini API requests until the key is revoked or restricted. ### Impact Assessment Exposure of the API key ...[truncated 510 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
native/main.swift:3277
Finding

Private Dictation Content Is Persisted in Plaintext Debug Logs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (143)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A speech-to-text skill description does not prepare users for uninstall logic that terminates processes, removes LaunchAgents, and deletes application/log files. Even if intended for cleanup, undisclosed destructive file/process actions increase operational risk and can be abused or trigger unexpected data loss.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A speech-to-text skill description does not prepare users for uninstall logic that terminates processes, removes LaunchAgents, and deletes application/log files. Even if intended for cleanup, undisclosed destructive file/process actions increase operational risk and can be abused or trigger unexpected data loss.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A speech-to-text skill description does not prepare users for uninstall logic that terminates processes, removes LaunchAgents, and deletes application/log files. Even if intended for cleanup, undisclosed destructive file/process actions increase operational risk and can be abused or trigger unexpected data loss.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Synthetic keyboard event generation enables the tool to send input to whichever application currently has focus, which is a strong control capability unrelated to mere transcription. This can cause unintended actions in terminals, password prompts, chats, or admin tools, and is especially risky because the prompt couples it with automatic clipboard replacement and no confirmation step.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · design-versions/v1-white-blue/main.swift (reported line 1119)May include surrounding context.

text
</head>
<body>

<!-- STEP 0: WELCOME -->
<div class="step active" id="step-0">
  <div class="welcome-content" style="flex:1; justify-content:center;">
    <div id="logoArea" class="app-icon app-icon-lg"><svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 512 512" fill="#000000"><g transform="translate(0,512) scale(0.1,-0.1)" stroke="none"><path d="M1966 4593 c-52 -19 -61 -29 -47 -51 6 -11 16 -11 47 -3 179 50 341 -76 368 -284 l6 -50 -53 -29 c-123 -70 -241 -239 -254 -369 l-6 -57 150 0 c133 0 152 -2 166 -18 21 -23 22 -46 2 -66 -12 -12 -43 -15 -153 -15 -75 1 -143 0 -149 0 -8 -1 -13 -17 -13 -46 l0 -44 156 -3 c134 -3 158 -5 167 -20 8 -12 8 -24 -1 -42 l-12 -26 -155 0 -155 0 0 -45 0 -45 153 0 c161 0 177 -4 177 -45 0 -41 -16 -45 -177 -45 l-153 0 0 -45 0 -45 153 0 c161 0 177 -4 177 -45 0 -41 -16 -45 -177 -45 l-153 0 0 -40 0 -40 83 -1 c268 -4 973 4 980 11 5 4 7 20 5 36 l-3 29 -158 5 c-125 4 -160 8 -167 20 -13 20 -12 33 3 53 10 14 36 17 167 19 l155 3 0 40 0 40 -155 3 c-131 2 -157 5 -167 19 -17 22 -16 38 3 57 13 13 42 16 165 16 l149 0 6 24 c3 14 3 34 -1 45 -6 20 -13 21 -155 21 -147 0 -150 0 -165 24 -13 19 -14 29 -5 45 10 20 19 21 165 21 l155 0 0 45 0 45 -145 0 c-132 0 -147 2 -165 20 -11 11 -20 25 -20 30 0 6 9 19 20 30 18 18 33 20 170 20 171 0 161 -7 135 95 -34 128 -117 243 -232 317 l-65 43 5 50 c13 122 81 226 180 274 42 20 58 23 120 18 40 -3 81 -7 92 -9 14 -2 21 3 23 19 3 19 -5 24 -49 37 -66 20 -102 20 -165 1 -68 -20 -140 -69 -180 -124 -39 -54 -74 -149 -74 -204 l0 -39 -52 9 c-67 10 -201 10 -253 0 l-41 -8 -11 63 c-15 88 -49 154 -110 216 -88 89 -205 121 -307 85z"/><path d="M1787 2982 c-13 -14 -17 -39 -17 -110 0 -87 1 -92 25 -108 l25 -16 0 -347 c0 -365 5 -410 50 -515 58 -137 181 -267 319 -340 72 -38 197 -76 248 -76 l33 0 0 -273 0 -274 -132 -7 c-198 -9 -394 -35 -468 -59 -56 -19 -65 -25 -65 -46 0 -30 41 -45 170 -66 251 -40 825 -45 1095 -11 142 18 260 50 260 70 0 35 -79 66 -220 85 -99 14 -317 31 -396 31 l-64 0 0 274 0 273 55 7 c290 34 541 271 594 560 7 35 11 196 11 390 0 320 1 332 20
...[truncated 25 chars]

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The page states the product is powered by Google Gemini and describes live streaming transcription, but it does not clearly disclose that users' speech/audio is transmitted to Google's external service for processing. Because this tool captures potentially sensitive spoken content and inserts text at the cursor, missing disclosure creates a significant privacy and data-handling risk for users who may assume local processing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This Vite config injects GEMINI_API_KEY directly into client-side code using define, which causes the secret to be embedded in the built frontend artifact and retrievable by any user of the site. Exposing an API key in a public landing page is dangerous because attackers can extract and abuse it for unauthorized API usage, cost consumption, and potential access to associated backend capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The configuration explicitly exposes GEMINI_API_KEY to browser-accessible code without any protective boundary, meaning the credential is not merely used internally but delivered to end users. In the context of a speech-to-text/product landing page, there is no legitimate reason to ship a privileged secret to the client, which increases the likelihood of misuse and unauthorized third-party consumption.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · design-versions/v1-white-blue/website.html (reported line 164)May include surrounding context.

html
</head>
<body>

<!-- ═══ NAVBAR ═══ -->
<nav>
  <a href="#" class="nav-brand">
    <img src="logo-white.png" alt="虾BB" style="height:24px">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · docs/index.html (reported line 164)May include surrounding context.

html
</head>
<body>

<!-- ═══ NAVBAR ═══ -->
<nav>
  <a href="#" class="nav-brand">
    <img src="logo-white.png" alt="虾BB" style="height:24px">

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description states that the app uses the Gemini Live API and later instructs users to obtain a Gemini API key, which implies audio/transcript data is sent to Google's service. The page does not include a privacy or data-transmission warning, so users are not informed that spoken content may leave their device.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · native/main.swift (reported line 1311)May include surrounding context.

text
</head>
<body>

<!-- STEP 0: WELCOME -->
<div class="step active" id="step-0">
  <div class="welcome-content" style="flex:1; justify-content:center;">
    <!-- Lobster illustration placeholder -->

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · uninstall.sh (reported line 9)May include surrounding context.

sh
# Remove auto-start
launchctl unload ~/Library/LaunchAgents/com.xiabb.plist 2>/dev/null
rm -f ~/Library/LaunchAgents/com.xiabb.plist

# Remove app
rm -rf "/Applications/XiaBB.app"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · uninstall.sh (reported line 12)May include surrounding context.

sh
rm -f ~/Library/LaunchAgents/com.xiabb.plist

# Remove app
rm -rf "/Applications/XiaBB.app"

# Remove log
rm -f ~/Library/Logs/XiaBB.log

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · uninstall.sh (reported line 15)May include surrounding context.

sh
rm -rf "/Applications/XiaBB.app"

# Remove log
rm -f ~/Library/Logs/XiaBB.log

echo "Uninstalled."
echo "   Config and API key at ~/Tools/xiabb/ left intact."

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · uninstall.sh (reported line 19)May include surrounding context.

sh
echo "Uninstalled."
echo "   Config and API key at ~/Tools/xiabb/ left intact."
echo "   To fully remove: rm -rf ~/Tools/xiabb/"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · uninstall.sh (reported line 19)May include surrounding context.

sh
echo "Uninstalled."
echo "   Config and API key at ~/Tools/xiabb/ left intact."
echo "   To fully remove: rm -rf ~/Tools/xiabb/"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

Line L19 describes a hard language behavior: the mode will enforce the input language and prevent Chinese input from becoming English output. Because SQP-3 applies to all file types and flags language/locale constraints without user opt-in, this natural-language statement appears to impose a language policy rather than offering a choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README makes a strong minimization claim that the tool 'only does one thing' while later documenting translation, prompt optimization, and email generation. This is a deceptive or materially incomplete description of functionality, which can mislead users about the scope of AI processing and what kind of content may be sent to the model.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The text says the product does not try to be an AI assistant, but later advertises assistant-like behaviors such as translation, prompt generation, and email drafting. This inconsistency can reduce informed consent by causing users to underestimate the degree of generative AI involvement and the possible sensitivity of outputs and prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README describes sending recorded audio to Google Gemini APIs, but the setup and usage flow does not present a prominent, explicit warning that spoken content is transmitted to a third-party cloud service. Because this tool captures arbitrary dictated text and auto-pastes at the cursor, users may inadvertently send sensitive credentials, source code, business data, or personal information off-device without clear notice.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises installation commands and appears to rely on shell/environment capabilities, but it does not declare any tool scope such as permissions or allowed-tools. That creates an authorization gap: reviewers and users cannot clearly see that shell access and environment/API-key handling may occur, increasing the chance of unexpected command execution or secret exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description mentions Google Gemini and an API key, but it does not clearly warn that spoken audio and/or transcribed text may be transmitted to a third-party service. For a voice-input tool, that omission is privacy-relevant because users may dictate sensitive credentials, code, emails, or business information without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt directs uploading recorded microphone audio to an external Gemini API endpoint but does not require any disclosure, consent, or data-handling notice to the end user. In a voice tool, silent network transfer of spoken content can expose sensitive personal, business, or authentication-related information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.