Back to skill

Security audit

XiaChat MCP — AI Personality Matching

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-aligned, but it asks users to run an unpinned third-party MCP server and route sensitive personality, relationship, and chat data to an external service without clear consent and privacy boundaries.

Install only if you trust XiaChat and are comfortable sending personality profiles, quiz answers, chat exports, match data, and pre-chat transcripts to that service. Prefer a pinned and verified MCP server version, use a restricted API key, and avoid uploading private chat histories unless you have consent from the people in them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned Third-Party Package Is Automatically Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 28–30
Vulnerability Type: Unpinned and automatically executed third-party dependency
Risk Level: Medium

Vulnerable Code

json
"command": "npx",
"args": ["-y", "@xiachat/mcp-server"],
"env": {
  "XIACHAT_API_KEY": "xk_your_api_key"
}

Technical Analysis

The documented configuration invokes npx with -y to download and execute @xiachat/mcp-server without pinning an exact package version. The project contains no lockfile, package integrity hash, vendored implementation, or other mechanism that binds execution to a reviewed artifact.

Consequently, the effective executable can change after this audit whenever the registry's package resolution changes. Automatic confirmation through -y also removes an opportunity for the user to inspect the package and resolved version before execution. This creates a supply-chain risk if a future release, publisher account, package registry, or transitive dependency is compromised.

The package is not established as malicious by the reviewed file. The finding concerns the unsafe, mutable dependency execution pattern.

Attack Path

  1. An attacker compromises the package publisher account, the package distribution channel, or a transitive dependency used by a subsequently resolved release.
  2. The attacker publishes a malicious version under @xiachat/mcp-server or introduces malicious dependency code.
  3. A user applies the documented MCP configuration and starts or restarts the client.
  4. npx -y @xiachat/mcp-server resolves and downloads the mutable package version without interactive confirmation.
  5. The malicious package executes locally with the privileges of the MCP client process.
  6. During execution, the package may access the configured XIACHAT_API_KEY and other resources available to that process.

Impact Assessment

Successful exploitation could allow arbitrary code executi ...[truncated 436 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin @xiachat/mcp-server to a specific, reviewed version rather than allowing resolution to the latest release.
  2. Install the dependency through a manifest and lockfile that records the complete transitive dependency graph.
  3. Verify package integrity using registry integrity metadata, trusted checksums, or signed release artifacts.
  4. Remove automatic -y execution where practical so users can review the resolved package and version before installation.
  5. Document the package's official registry namespace, publisher identity, source repository, and release verification procedure.
  6. Run the MCP server with least privilege and isolate it from unrelated files and credentials.
  7. Restrict the API key to the minimum required permissions, avoid exposing it to unrelated processes, and establish a rotation procedure for suspected compromise.
  8. Re-audit each dependency update before changing the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description is broadly worded to trigger whenever a user wants to find compatible people, create profiles, or chat with personas, which can cause the agent to invoke this integration in situations where the user did not clearly consent to sending sensitive personal or conversation data to XiaChat. Because this skill handles matchmaking, personality profiling, and chat content, overbroad activation increases the chance of unnecessary third-party data exposure and unexpected external actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly supports processing highly sensitive personal data, including personality profiles, chat exports, compatibility scoring, and avatar-mediated conversations, but does not provide a clear privacy notice or warning that this data will be sent to an external service. In this context, users may unknowingly expose intimate behavioral, relational, and psychological information, making the omission materially dangerous.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.