xb-add-ai
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- Indirect Prompt Injection Surface: The skill facilitates building behaviors where the agent processes external data via queries and executes actions based on model-generated tool arguments. This creates a surface where untrusted input could influence agent actions.
- Ingestion points:
xb.ai.query,xb.ai.sendRealtimeInput, andxb.Tool(arguments provided by the LLM) as documented inSKILL.mdandreferences/current-api.md. - Capability inventory: The
xb.Toolimplementation inreferences/live-tools-grounding.mdallows the execution of application actions, which could be exploited if not properly secured. - Sanitization: The instructions explicitly advise validating tool arguments (types, ranges, target identity) and using allowlists to mitigate risks.
- Boundary markers: The skill recommends using explicit user disclosures and requiring visible confirmation for consequential actions to limit the impact of unexpected model behavior.
- Credential Management Considerations: The reference documentation in
references/current-api.mddescribes methods for loading API credentials that include using a localkeys.jsonfile or URL parameters. - Context: While these patterns involve sensitive credential handling, the documentation explicitly identifies them as risky for production environments (exposing keys to browser code) and recommends the use of server-controlled proxies or short-lived credentials for production applications.
- Sensitive Data Handling: The skill provides instructions for capturing and transmitting real-time sensor data, such as microphone audio and camera frames, to external AI providers.
- Mitigation: The guidelines in
SKILL.mdandreferences/live-tools-grounding.mdemphasize the necessity of user disclosure for each type of input and advise selecting the smallest necessary data observation to preserve privacy.
Audit Metadata