Back to skill

Security audit

WhoBot 呼波特 · AI电话数字员工

Security checks for vulnerabilities and agentic risk

Overview

The skill's phone-call workflow is mostly coherent, but it should be reviewed because it tells the agent to silently install an unpinned npm CLI before use.

Review this before installing if you do not want an agent to automatically fetch and run the latest Whobot npm CLI. The phone-call and login flows are disclosed and mostly gated by confirmation, but the installation step should ideally be pinned to a reviewed version and require explicit approval.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (52)

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill instructs the agent to install and execute a package from npm using the mutable tag @latest, which is not version-pinned. This creates a supply-chain risk: if the package, dependency chain, or publish target is compromised, the agent may fetch and run attacker-controlled code on the host at execution time.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly allows automatic CLI installation without user confirmation, but the skill description does not clearly warn that software may be installed on the system. This reduces user awareness and consent around a host-modifying action, increasing the chance of unexpected package installation and making any supply-chain issue more dangerous in practice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON manifest includes ask phrases "网页语音通话" and "实际电话" as activation-like prompts, but it does not define when this skill should trigger versus when similar everyday mentions should be ignored. The phrases are short and broad enough to match ordinary conversation about web calls or real phone calls, creating a risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest hard-codes the user-facing choice text to Chinese ("网页语音通话") with no indication that the user can select a preferred language or locale. This is a natural-language policy concern because it enforces a specific language in skill-facing text without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest includes a Chinese-only userChoice value, which appears to hard-code the skill's displayed language. The file does not indicate that language is user-selectable or that the skill is intentionally limited to a Chinese locale, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The JSON sets userChoice to the Chinese phrase 网页语音通话, indicating a fixed locale/language choice in the skill definition. There is no accompanying indication that the user can choose their preferred language or that this locale restriction is justified, which violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The JSON error payload contains a user-facing message only in Chinese ("凭据需要恢复") with no indication that the skill is region-specific or that language is configurable. This can violate language/locale policy because it imposes a specific language on users without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The JSON error payload contains a user-facing message only in Chinese: "当前 Installation 属于其他账号". For a general-purpose error fixture, this imposes a specific language without any indication of user opt-in or that the file is intended for a Chinese-only locale, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The JSON contains a user-facing error message string, "需要手机号验证", in Chinese with no indication that the skill is locale-specific or that users can choose their preferred language. This creates a natural-language policy concern because it imposes a specific language on all users without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The JSON error payload contains a user-facing message only in Chinese ("企业上下文已变化") with no indication that the locale is configurable or tied to a documented region-specific context. This can violate language/locale policy because it imposes a specific language on all users without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language string "上游不可用" is presented as the error message with no indication that the user can choose their preferred language or that this file is intended only for a Chinese-language or region-specific context. This can violate language/locale policy because it hard-codes a specific language in a user-facing response.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The error message string is written only in Chinese ("上游不可用") in a JSON file, which applies to the natural-language policy rule for all file types. There is no indication in this file that the locale is user-selected or that the skill is intentionally region-specific, so this may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The natural-language values in the skillBehavior fields are uniformly written in Chinese, indicating the skill's behavioral instructions are fixed to a specific language. The file does not offer any user opt-in, language selection, or documented justification for a Chinese-only locale, which matches the policy category for forced language or locale constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation explicitly says not to ask the user for confirmation before performing installation, then provides a package execution command. Removing consent before install/update actions is dangerous because it authorizes code execution and environment changes without user approval, which can lead to unauthorized software installation or silent supply-chain compromise. The risk is amplified here because the same file also uses npx with @latest, combining automatic execution with unreviewed package retrieval.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The installation command uses npx --yes @whobot/cli@latest install, which pulls and executes the latest package version at runtime without pinning to a reviewed version. That creates a supply-chain risk: a compromised upstream package, malicious publish, or breaking change could be executed immediately in the agent environment. In this skill context, the danger is increased because the document instructs the agent to run the command automatically as part of setup.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing instructions in the file are written in Chinese, and there is no indication that other languages are supported or that the Chinese-only behavior is optional. Per SQP-3, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale limitation is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file instructs the agent to initiate free trial outbound calls to a specified or account-bound phone number, but it provides no requirement to verify recipient consent, warn about privacy implications, or prevent use against third parties. In a phone-calling skill, this omission increases the risk of harassment, unauthorized contact, and misuse of personal phone numbers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest includes Chinese prompt/recommendation strings in ask and recommend with no indication that the skill is language-specific or that users can choose another language. This can violate language/locale policy expectations when a skill is otherwise not documented as region- or language-scoped.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The user-facing values in ask, recommend, and userChoice are hard-coded in Chinese, which may impose a specific language/locale without indicating that the user selected it or that the skill is region-specific. This can violate language-choice policy when no opt-in or justification is present in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The notes field contains an instruction only in Chinese, which imposes a specific language/locale in the skill metadata without offering user choice or explaining a region-specific need. This matches the policy category for language or locale constraints expressed in natural language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest sets userChoice to the Chinese phrase 网页语音通话, which indicates a fixed language/locale in the skill configuration. There is no visible indication in this file that the user can choose or opt into that language, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The note at L28 includes Chinese text ('查询失败交回用户控制,不得立即无限循环 cancel 或 recover') with no indication that language choice is optional or contextually required. This can violate language/locale policy because it imposes a specific language in a user-facing or maintainer-facing instruction without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This JSON manifest contains a natural-language note only in Chinese: "用户提问或叫停时先响应;停止等待不等于挂断;被取消或未完成的 wait 不能解释为空 HTTP 响应。" A single-language constraint in config text can violate language/locale policy when no user choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This manifest-style JSON includes natural-language fields such as "售前顾问", "教育", and "招生" in a single fixed language. Because SQP-3 applies to all file types, this can be flagged as a locale-policy concern when the file provides user-facing content without offering any language choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The JSON error payload hard-codes the message "需要登录" in Chinese, with no indication that language selection is user-configurable or that this file is intended only for a Chinese locale. This can violate language/locale policy expectations because it forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.