T09 · Insecure Skill Coding Practices
- Location
script/ult-xiaoyou.py:162- Finding
Microphone Audio Continues Transmitting After Push-to-Talk Release
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This remote voice-client skill can keep sending microphone audio after push-to-talk is released and prints connection credentials to the console.
Review carefully before installing. This skill connects to external services, sends device and audio data, listens for global keyboard events, and may continue transmitting microphone audio after the user believes recording has stopped. Do not run it around sensitive conversations, and avoid sharing its console output because it may contain connection credentials.
script/ult-xiaoyou.py:162Microphone Audio Continues Transmitting After Push-to-Talk Release
script/ult-xiaoyou.py:136Dynamically Issued MQTT Credentials Are Printed in Plaintext
script/requirements.txt:8Unused Third-Party Dependency Is Installed Without a Version Pin
cryptography==44.0.0 is associated with multiple advisories, including vulnerable bundled OpenSSL components and cryptographic attack surface issues. In any skill relying on encryption, TLS, or certificate handling, outdated cryptography packages can undermine confidentiality and integrity guarantees.
The script opens the microphone, continuously reads audio, and transmits encoded audio to a remote server, but does not provide explicit informed consent that speech is uploaded off-device. Even though recording is gated by a space keypress, the user-facing prompts emphasize interaction rather than clearly disclosing remote audio transmission and associated privacy implications.
requests==2.32.3 is flagged with published advisories, including a .netrc credential leak issue and other known weaknesses. If the skill processes attacker-controlled URLs or performs network retrievals, a vulnerable HTTP client can expose credentials or enable unsafe file/network handling.
User-facing strings throughout the script are presented only in Chinese, including setup instructions, prompts, status messages, and errors. This forces a specific language/locale without offering the user a choice or documenting the locale restriction as a justified regional constraint.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 获取设备唯一标识
DEVICE_ID, MAC_ADDR = get_or_create_device_id()
OTA_VERSION_URL = 'https://api.tenclass.net/xiaozhi/ota/'
mqtt_info = {}
aes_opus_info = {
"type": "hello",
The script sends substantial device and network metadata to a remote HTTPS endpoint, including MAC address, local IP, SSID, RSSI, hardware details, and partition/application information, without meaningful user disclosure or consent. This creates privacy and fingerprinting risk because the remote service can uniquely identify the user and environment and correlate future activity.
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
# 加密数据,添加nonce
encrypt_encoded_data = aes_ctr_encrypt(bytes.fromhex(key), bytes.fromhex(new_nonce), bytes(encoded_data))
data = bytes.fromhex(new_nonce) + encrypt_encoded_data
sent = udp_socket.sendto(data, (server_ip, server_port))
except Exception as e:
print(f"{COLORS['ERROR']}发送音频错误:{str(e)}{COLORS['RESET']}")
finally:
The documentation states that the application will automatically connect on startup, but it does not clearly warn users beforehand about immediate network activity or what remote service will be contacted. This reduces informed consent and can expose users to unexpected data transmission or connection to an untrusted endpoint, especially for a voice client that may handle microphone-related features.
The dependency pycaw is unpinned, so installs may resolve to different versions over time, including versions with unexpected behavior or newly introduced vulnerabilities. In a security-sensitive skill that also includes audio and input-control libraries, lack of version pinning reduces build reproducibility and weakens supply-chain control.
pynput==1.7.7
opuslib==3.0.1
cryptography==44.0.0
pycaw
The natural-language documentation is presented entirely in Chinese, and the file does not indicate that this language choice is optional or justified by a region-specific scope. This can violate language/locale policy where skills are expected to offer a user choice or clearly document locale constraints.
No suspicious patterns detected.