Back to skill

Security audit

Arrhythmia Early Warning Analysis Tool | 心律失常早期预警分析工具

Security checks for vulnerabilities and agentic risk

Overview

This health-analysis skill is mostly coherent, but it silently creates or reuses cloud-linked identities and stores authentication tokens while handling sensitive face-video health data.

Review before installing. This skill uploads or references face-video health inputs through a remote service, can query cloud-stored report history, silently creates or reuses an internal user identity, and stores tokens locally in the workspace data directory. Install only if that account linkage, cloud processing, and local token persistence match your privacy expectations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (50)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code behavior reportedly includes workspace inspection, local identity generation and persistence, authenticated outbound requests, and backend auto-registration/login, none of which are clearly reflected in the user-facing medical description. This is dangerous because it combines sensitive biometric/health uploads with covert identity management and networked account operations, increasing privacy and abuse risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code behavior reportedly includes workspace inspection, local identity generation and persistence, authenticated outbound requests, and backend auto-registration/login, none of which are clearly reflected in the user-facing medical description. This is dangerous because it combines sensitive biometric/health uploads with covert identity management and networked account operations, increasing privacy and abuse risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code behavior reportedly includes workspace inspection, local identity generation and persistence, authenticated outbound requests, and backend auto-registration/login, none of which are clearly reflected in the user-facing medical description. This is dangerous because it combines sensitive biometric/health uploads with covert identity management and networked account operations, increasing privacy and abuse risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code behavior reportedly includes workspace inspection, local identity generation and persistence, authenticated outbound requests, and backend auto-registration/login, none of which are clearly reflected in the user-facing medical description. This is dangerous because it combines sensitive biometric/health uploads with covert identity management and networked account operations, increasing privacy and abuse risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code behavior reportedly includes workspace inspection, local identity generation and persistence, authenticated outbound requests, and backend auto-registration/login, none of which are clearly reflected in the user-facing medical description. This is dangerous because it combines sensitive biometric/health uploads with covert identity management and networked account operations, increasing privacy and abuse risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code behavior reportedly includes workspace inspection, local identity generation and persistence, authenticated outbound requests, and backend auto-registration/login, none of which are clearly reflected in the user-facing medical description. This is dangerous because it combines sensitive biometric/health uploads with covert identity management and networked account operations, increasing privacy and abuse risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code behavior reportedly includes workspace inspection, local identity generation and persistence, authenticated outbound requests, and backend auto-registration/login, none of which are clearly reflected in the user-facing medical description. This is dangerous because it combines sensitive biometric/health uploads with covert identity management and networked account operations, increasing privacy and abuse risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code behavior reportedly includes workspace inspection, local identity generation and persistence, authenticated outbound requests, and backend auto-registration/login, none of which are clearly reflected in the user-facing medical description. This is dangerous because it combines sensitive biometric/health uploads with covert identity management and networked account operations, increasing privacy and abuse risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code behavior reportedly includes workspace inspection, local identity generation and persistence, authenticated outbound requests, and backend auto-registration/login, none of which are clearly reflected in the user-facing medical description. This is dangerous because it combines sensitive biometric/health uploads with covert identity management and networked account operations, increasing privacy and abuse risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code behavior reportedly includes workspace inspection, local identity generation and persistence, authenticated outbound requests, and backend auto-registration/login, none of which are clearly reflected in the user-facing medical description. This is dangerous because it combines sensitive biometric/health uploads with covert identity management and networked account operations, increasing privacy and abuse risks.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "arrhythmia-early-warning-analysis"
description: "Based on facial video, identifies abnormal rhythms such as premature beats, atrial fibrillation, tachycardia/bradycardia, assists in early detection of heart health risks. | 心律失常早期预警技能,基于面部视频识别早搏、房颤、心动过速/心动过缓等异常节律,辅助心脏健康风险早发现"
version: "1.0.18"
license: "MIT-0"
---

# 💓 Arrhythmia Early Warning Analysis Tool | 心律失常早期预警分析工具

> **智能健康/识别分析中枢** · 图片/视频智能分析 · 结构化报告 · 历史报告云端查询

---

## 🧭 技�

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill states that historical report lookup must directly query a cloud API, but it does not present a corresponding privacy notice or consent cue to the user. Because the subject matter is health-related, silent cloud retrieval of historical reports materially increases privacy risk and may expose sensitive medical data through unexpected backend access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file implements a generic API wrapper with broad HTTP and CRUD capabilities (GET/POST/PUT/DELETE, add/edit/delete/list/page) that are not specific to facial-video arrhythmia analysis. In a medical early-warning skill, such unrestricted remote access expands the attack surface and could be repurposed to call unrelated endpoints, exfiltrate data, or perform unauthorized actions if other parts of the skill can influence the URL or request payloads.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code exposes direct remote resource modification primitives through add, edit, delete, http_post, http_put, and http_delete methods, all forwarding arbitrary parameters to lower-level request utilities. Because the skill's declared purpose is analysis of heart rhythm from facial video, these modification capabilities are unjustified and dangerous: they could enable tampering with external systems, destructive operations, or abuse of any authenticated backend reachable by RequestUtil.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file belongs to an arrhythmia early-warning skill, yet it implements generic user/account persistence unrelated to that medical purpose. In a health-analysis context, unnecessary account management expands the attack surface and increases the chance of collecting or retaining personal data outside the declared function of the skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The User model stores identity and authentication-related data including username, realname, email, token, and open_token, which is difficult to justify for facial-video arrhythmia screening. In this medical context, combining health-related processing with excess identifiers and tokens materially raises privacy, compliance, and account-compromise risk if the local database is accessed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This utility code provisions and resolves user identities by reading workspace files, consulting a local database, and creating default identifiers, which is unrelated to the declared purpose of facial-video arrhythmia analysis. In a medical-analysis skill, hidden identity management expands the trust boundary and can silently bind analysis activity to persistent user identities without clear user awareness or necessity.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The HTTP utility automatically performs remote login/registration flows, injects auth headers, and reuses persisted tokens when making requests. That behavior materially exceeds the manifest's stated medical-analysis function and could cause undisclosed account creation, identity binding, and transmission of user-associated data to external services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This code can silently create or retrieve remote user accounts, fetch tokens, and persist them locally for later reuse. In the context of a healthcare-adjacent analysis skill, that is especially dangerous because users may not expect hidden account lifecycle operations tied to sensitive health-related interactions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill manifest declares no explicit tool or permission scope even though the described workflow clearly relies on shell execution, filesystem access, environment/config access, and outbound network/API calls. This weakens containment and makes it easier for the skill to exercise broader capabilities than a reviewer or runtime policy might expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The history-query trigger phrases are broad enough that ordinary conversation about reports could automatically invoke cloud retrieval of historical medical-related data. In a health context, accidental triggering can reveal sensitive report metadata or cause unexpected backend access without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill says uploaded attachments are automatically saved to local files, but it does not disclose this persistence to the user. For face videos and health-related media, undisclosed local storage increases privacy exposure, accidental retention, and the risk of secondary access from other processes or users on the system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file describes an API that supports file uploads and exporting full reports, both of which can affect user data and privacy. Under the markdown-specific SQP-2 criteria, the description should include a warning or disclosure about handling sensitive data, but none is present in the documented interface summary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Natural-language strings in the argument parser and runtime messages force a specific language for all users. Under the stated policy, locale-specific behavior should either be optional, user-selectable, or clearly documented as region-specific and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code file allows analysis from a network URL via --url, and the surrounding flow invokes the analysis skill without disclosing whether the referenced media or derived data will be sent to a service. Although the script prints progress, it does not provide a privacy or network-use warning before processing potentially sensitive medical data.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2