pp-3cx-xapi

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill fetches its management binary and MCP server from the author's official GitHub repository and NPM registry. These resources originate from the skill vendor and are essential for its operation.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The tool features a delivery flag that allows command output to be posted to arbitrary webhook URLs. This could be used to exfiltrate sensitive PBX configuration data to unauthorized endpoints.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection as it processes untrusted external data. 1. Ingestion points: PBX configuration data mirrored locally, CSV files for provisioning, and natural language strings provided for command discovery. 2. Boundary markers: The skill instructions do not specify any delimiters or instructions to ignore embedded commands. 3. Capability inventory: The binary can modify phone system settings and perform network exfiltration. 4. Sanitization: There is no documented validation or sanitization of the data processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 08:18 AM
Security Audit — agent-trust-hub — pp-3cx-xapi