Back to skill

Security audit

LiveVideoStore

Security checks for vulnerabilities and agentic risk

Overview

This remote voice-client skill can keep sending microphone audio after push-to-talk is released and prints connection credentials to the console.

Review carefully before installing. This skill connects to external services, sends device and audio data, listens for global keyboard events, and may continue transmitting microphone audio after the user believes recording has stopped. Do not run it around sensitive conversations, and avoid sharing its console output because it may contain connection credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
script/ult-xiaoyou.py:162
Finding

Microphone Audio Continues Transmitting After Push-to-Talk Release

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
script/ult-xiaoyou.py:136
Finding

Dynamically Issued MQTT Credentials Are Printed in Plaintext

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
script/requirements.txt:8
Finding

Unused Third-Party Dependency Is Installed Without a Version Pin

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Known Vulnerable Dependency: cryptography==44.0.0 — 12 advisory(ies): GHSA-537c-gmf6-5ccf (Vulnerable OpenSSL included in cryptography wheels); CVE-2024-12797 (Vulnerable OpenSSL included in cryptography wheels); CVE-2026-69247 (cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle th) +9 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

cryptography==44.0.0 is associated with multiple advisories, including vulnerable bundled OpenSSL components and cryptographic attack surface issues. In any skill relying on encryption, TLS, or certificate handling, outdated cryptography packages can undermine confidentiality and integrity guarantees.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script opens the microphone, continuously reads audio, and transmits encoded audio to a remote server, but does not provide explicit informed consent that speech is uploaded off-device. Even though recording is gated by a space keypress, the user-facing prompts emphasize interaction rather than clearly disclosing remote audio transmission and associated privacy implications.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: requests==2.32.3 — 4 advisory(ies): CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2026-25645 (Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility func); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs) +1 more

Medium
Category
Supply Chain
Confidence
91% confidence
Finding

requests==2.32.3 is flagged with published advisories, including a .netrc credential leak issue and other known weaknesses. If the skill processes attacker-controlled URLs or performs network retrievals, a vulnerable HTTP client can expose credentials or enable unsafe file/network handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

User-facing strings throughout the script are presented only in Chinese, including setup instructions, prompts, status messages, and errors. This forces a specific language/locale without offering the user a choice or documenting the locale restriction as a justified regional constraint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · script/ult-xiaoyou.py (reported line 82)May include surrounding context.

python
# 获取设备唯一标识
DEVICE_ID, MAC_ADDR = get_or_create_device_id()

OTA_VERSION_URL = 'https://api.tenclass.net/xiaozhi/ota/'
mqtt_info = {}
aes_opus_info = {
    "type": "hello",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends substantial device and network metadata to a remote HTTPS endpoint, including MAC address, local IP, SSID, RSSI, hardware details, and partition/application information, without meaningful user disclosure or consent. This creates privacy and fingerprinting risk because the remote service can uniquely identify the user and environment and correlate future activity.

Content

No source excerpt is available for this finding.

Tainted flow: 'data' from socket.socket.recvfrom (line 215, network input) → socket.socket.sendto (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · script/ult-xiaoyou.py (reported line 192)May include surrounding context.

python
# 加密数据,添加nonce
            encrypt_encoded_data = aes_ctr_encrypt(bytes.fromhex(key), bytes.fromhex(new_nonce), bytes(encoded_data))
            data = bytes.fromhex(new_nonce) + encrypt_encoded_data
            sent = udp_socket.sendto(data, (server_ip, server_port))
    except Exception as e:
        print(f"{COLORS['ERROR']}发送音频错误:{str(e)}{COLORS['RESET']}")
    finally:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that the application will automatically connect on startup, but it does not clearly warn users beforehand about immediate network activity or what remote service will be contacted. This reduces informed consent and can expose users to unexpected data transmission or connection to an untrusted endpoint, especially for a voice client that may handle microphone-related features.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency pycaw is unpinned, so installs may resolve to different versions over time, including versions with unexpected behavior or newly introduced vulnerabilities. In a security-sensitive skill that also includes audio and input-control libraries, lack of version pinning reduces build reproducibility and weakens supply-chain control.

Content

Scanner excerpt · script/requirements.txt (reported line 8)May include surrounding context.

text
pynput==1.7.7
opuslib==3.0.1
cryptography==44.0.0
pycaw

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language documentation is presented entirely in Chinese, and the file does not indicate that this language choice is optional or justified by a region-specific scope. This can violate language/locale policy where skills are expected to offer a user choice or clearly document locale constraints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.