Back to skill

Security audit

XiaoPai Player Control

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent XiaoPai media-player controller, but users should treat it as a local-network remote control that can disrupt the player if powerful commands are used.

Install only if you want an agent to control XiaoPai players reachable from this machine. Use it on trusted local networks, select or confirm the target device/IP yourself, and require explicit confirmation before power, reboot, delete, or other disruptive commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/xiaopai-ctl.sh:69
Finding

Unrestricted User-Controlled Network Destination

Content
View full analysis
/dev/null || echo '{"error":"connection failed"}' ``` ### Technical Analysis The first command-line argument is treated as the player IP and used directly as the destination for `curl` and `nc`. The script does not establish that the value is a valid IP address, belongs to an approved LAN range, or corresponds to a XiaoPai device discovered through mDNS. Although the destination ports are fixed to HTTP port 9050 and TCP port 9051, an attacker who can influence the arguments passed by the Agent can cause connections to arbitrary reachable hosts on those ports. This creates a constrained arbitrary-network-request primitive and violates the documented assumption that commands are directed only to a XiaoPai player on the same LAN. The use of shell quoting prevents ordinary shell command injection through this parameter, but it does not prevent network destination manipulation. ### Attack Path 1. An attacker induces the Agent to invoke the Skill with an attacker-selected hostname or IP address. 2. The value is assigned directly to `IP`. 3. For control operations, the script constructs an HTTP URL from that value and invokes `curl`. 4. For status operations, the script passes the value directly to `nc`. 5. The host running the Skill connects to the selected destination on port 9050 or 9051. 6. The attacker can use the resulting behavior to probe reachable services or send XiaoPai-compatible requ ...[truncated 582 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/xiaopai-ctl.sh:73
Finding

Raw Query Parameter Fallback When URL Encoding Is Unavailable

Content
View full analysis
/dev/null \ || python -c "import urllib,sys; print(urllib.quote(sys.argv[1]))" "$1" 2>/dev/null \ || printf '%s' "$1" } ``` The returned value is inserted into request query strings: ```bash ENCODED=$(url_encode "$3") curl -s "${BASE}/xiaopai/play?videopath=${ENCODED}" ``` ```bash ENCODED=$(url_encode "$3") curl -s "${BASE}/xiaopai/play?videoname=${ENCODED}" ``` ### Technical Analysis The function first attempts URL encoding with Python 3 and then Python 2. If neither command succeeds, it silently returns the original input without encoding it. Raw input can contain query delimiters such as `&`, `#`, `?`, and `=`. When this value is concatenated into the URL, these characters can change the structure or interpretation of the HTTP request instead of remaining part of the intended media path or name. For example, a malicious `play-path` argument containing `&videoname=...` can introduce a second query parameter. The protocol documentation states that `videoname` takes priority when both `videopath` and `videoname` are present, so the player may perform a different playback action than the caller intended. This condition is reachable when neither compatible Python interpreter is installed or when both encoding commands fail. ### Attack Path 1. The host lacks both a working Python 3 encoder and a compatible Python 2 encoder. 2. An attacker supplies a media path containing HTTP query delimiters, such as an appended `&videoname=...` parameter. 3. Both Python encoding attempts fail. 4. The `printf` fallback returns the attacker's input unchanged. 5. The raw value is concatenated into the request URL. 6. The player parses the injected delimiter as query syntax an ...[truncated 653 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/xiaopai-ctl.sh:56
Finding

Unpinned Third-Party Dependency Installation Guidance

Content
View full analysis
/dev/null || echo "Error: install zeroconf (pip3 install zeroconf) or use dns-sd / avahi-browse." ``` ```bash echo " - python3 + zeroconf (pip3 install zeroconf)" ``` ### Technical Analysis When the Python discovery fallback cannot import `zeroconf`, the script instructs the user to run `pip3 install zeroconf` without specifying a reviewed version, cryptographic hash, package index, or locked dependency file. The script does not automatically run this installation command, which substantially limits the immediate risk. Nevertheless, a user following the generated instruction will retrieve whichever package version the configured package index currently serves. The installed code can therefore change after the Skill itself has been audited. Python package installation can execute package build or installation logic with the privileges of the invoking user. An unpinned dependency consequently reduces reproducibility and leaves the setup process dependent on the continuing integrity of the package registry, account, name resolution, and local package-manager configuration. ### Attack Path 1. Neither `dns-sd` nor `avahi-browse` is available, so the script selects Python discovery. 2. The `zeroconf` import fails because the package is absent. 3. The script displays `pip3 install zeroconf`. 4. The user follows the instruction without pinning a version or validating a hash. 5. `pip` retrieves the package and its transitive dependencies from its configured package source. 6. If the source, package account, dependency chain, or local index configuration is compromised, installation logic executes under the user's privileges. ### Impact Assessment There is no direct automatic exploitation path in the audited script because it only prints installation guidance. ...[truncated 424 chars]
Remediation
View remediation
--hash=sha256: ``` 3. Recommend installation with hash verification: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 4. Document the expected package registry and avoid untrusted or implicitly configured indexes. 5. Review and pin transitive dependencies where the installation model requires them. 6. Prefer an isolated virtual environment rather than a privileged or system-wide installation. 7. Do not recommend running package installation with `sudo`. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation lists a reboot command mapped to PowerManager.reboot() and labels it destructive, but provides no operational warning, permission boundary, or confirmation requirement. In this skill context, that makes remote denial-of-service straightforward: a user request or prompt injection could cause an immediate device reboot over LAN, interrupting service and potentially enabling repeated disruption.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents shell and network operations that can discover devices on the LAN and send unauthenticated control requests, but it does not declare any explicit tool scope or permission boundaries. That omission increases the chance an agent can invoke network and shell capabilities more broadly than intended, reducing transparency and making misuse or lateral network interaction harder to govern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The remote-control interface exposes potentially destructive or disruptive commands such as power off, reboot, stop, reset-like functions, and rapid navigation/control without consistently requiring confirmation at the point of use. In an agent context, this could let a prompt trigger unwanted device disruption on the local network, especially because the protocol appears unauthenticated and intended for immediate execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The protocol reference exposes unauthenticated remote control and playback actions over LAN without any cautionary guidance about trust boundaries, authorization, or user confirmation. In a skill specifically designed to control a media player, this omission is dangerous because it normalizes sending commands to a device that may accept sensitive or disruptive actions from any reachable client.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.