Back to skill

Security audit

Child Happy Moment Capture & Positive Reinforcement | 儿童开心时刻识别与正向激励

Security checks for vulnerabilities and agentic risk

Overview

This skill is a cloud-connected child video monitoring tool that mostly matches its stated purpose, but it silently creates/reuses identities and stores authentication tokens while handling highly sensitive footage of minors.

Review this carefully before installing. Use it only where you have explicit guardian consent for every child captured, understand that media and report data may go to LifeEmergence cloud endpoints, and are comfortable with the skill creating/reusing a local identity and storing session tokens in the workspace data directory. Prefer a version that makes consent, retention, deletion, pause/opt-out, remote storage, and token handling explicit and controllable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (51)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied behavior indicates remote HTTP requests, authentication/token handling, local file access, credential-like file reads, and local user/database operations that are not disclosed in the child-behavior monitoring description. This is especially dangerous in a children's surveillance context because hidden credentials, local identity creation, and remote service integration can expose sensitive media and metadata far beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied behavior indicates remote HTTP requests, authentication/token handling, local file access, credential-like file reads, and local user/database operations that are not disclosed in the child-behavior monitoring description. This is especially dangerous in a children's surveillance context because hidden credentials, local identity creation, and remote service integration can expose sensitive media and metadata far beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied behavior indicates remote HTTP requests, authentication/token handling, local file access, credential-like file reads, and local user/database operations that are not disclosed in the child-behavior monitoring description. This is especially dangerous in a children's surveillance context because hidden credentials, local identity creation, and remote service integration can expose sensitive media and metadata far beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied behavior indicates remote HTTP requests, authentication/token handling, local file access, credential-like file reads, and local user/database operations that are not disclosed in the child-behavior monitoring description. This is especially dangerous in a children's surveillance context because hidden credentials, local identity creation, and remote service integration can expose sensitive media and metadata far beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied behavior indicates remote HTTP requests, authentication/token handling, local file access, credential-like file reads, and local user/database operations that are not disclosed in the child-behavior monitoring description. This is especially dangerous in a children's surveillance context because hidden credentials, local identity creation, and remote service integration can expose sensitive media and metadata far beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied behavior indicates remote HTTP requests, authentication/token handling, local file access, credential-like file reads, and local user/database operations that are not disclosed in the child-behavior monitoring description. This is especially dangerous in a children's surveillance context because hidden credentials, local identity creation, and remote service integration can expose sensitive media and metadata far beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied behavior indicates remote HTTP requests, authentication/token handling, local file access, credential-like file reads, and local user/database operations that are not disclosed in the child-behavior monitoring description. This is especially dangerous in a children's surveillance context because hidden credentials, local identity creation, and remote service integration can expose sensitive media and metadata far beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied behavior indicates remote HTTP requests, authentication/token handling, local file access, credential-like file reads, and local user/database operations that are not disclosed in the child-behavior monitoring description. This is especially dangerous in a children's surveillance context because hidden credentials, local identity creation, and remote service integration can expose sensitive media and metadata far beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied behavior indicates remote HTTP requests, authentication/token handling, local file access, credential-like file reads, and local user/database operations that are not disclosed in the child-behavior monitoring description. This is especially dangerous in a children's surveillance context because hidden credentials, local identity creation, and remote service integration can expose sensitive media and metadata far beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied behavior indicates remote HTTP requests, authentication/token handling, local file access, credential-like file reads, and local user/database operations that are not disclosed in the child-behavior monitoring description. This is especially dangerous in a children's surveillance context because hidden credentials, local identity creation, and remote service integration can expose sensitive media and metadata far beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied behavior indicates remote HTTP requests, authentication/token handling, local file access, credential-like file reads, and local user/database operations that are not disclosed in the child-behavior monitoring description. This is especially dangerous in a children's surveillance context because hidden credentials, local identity creation, and remote service integration can expose sensitive media and metadata far beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied behavior indicates remote HTTP requests, authentication/token handling, local file access, credential-like file reads, and local user/database operations that are not disclosed in the child-behavior monitoring description. This is especially dangerous in a children's surveillance context because hidden credentials, local identity creation, and remote service integration can expose sensitive media and metadata far beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied behavior indicates remote HTTP requests, authentication/token handling, local file access, credential-like file reads, and local user/database operations that are not disclosed in the child-behavior monitoring description. This is especially dangerous in a children's surveillance context because hidden credentials, local identity creation, and remote service integration can expose sensitive media and metadata far beyond user expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill promotes continuous monitoring, automatic capture, and cloud-linked handling of children's images and videos without a prominent upfront privacy and consent warning. In the context of minors and fixed cameras in homes or schools, this is highly dangerous because it normalizes surveillance of children and may lead to unlawful or non-consensual collection, upload, and sharing of extremely sensitive data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation requires historical report retrieval from a cloud API but does not prominently warn users that sensitive child-related media and metadata may be transmitted off-device and fetched from remote systems. This undermines informed consent and can expose families or institutions to privacy and compliance violations if they assume local-only processing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code reads a workspace identity file, searches local user records, and creates fallback identities automatically, none of which is justified by the stated camera-based happy-moment detection feature. In a child-monitoring context, silent identity derivation and persistence are especially sensitive because they can link captured events to hidden accounts and enable unexpected backend tracking.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility performs remote account login/registration, token acquisition, persistence, and automatic identity resolution that are unrelated to the declared child-happy-moment capture purpose. In this skill context, hidden account bootstrapping and outbound authentication materially increase the attack surface and enable undisclosed data flows or backend coupling without clear user consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares broad operational behavior that implies shell, file, network, and environment access, but it does not explicitly constrain or disclose allowed tools. In a skill handling children's videos and cloud interactions, missing tool scoping increases the risk of over-privileged execution, unintended data access, and abuse of local or remote resources.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description specifies outputs such as '开心日记' and an encouragement sound like '你真棒!' as built-in behavior. This indicates a fixed language/locale experience without any stated user opt-in or language selection, which can violate language-choice policy expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill mandates hidden identity initialization and automatic reuse or creation of a default local user, even though that is not necessary for the stated analysis task. Silent identity binding is dangerous because it can associate sensitive child videos and reports with the wrong account, obscure consent boundaries, and make auditability difficult.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is marketed as analyzing children's happy moments, but the implementation routes requests through a generic/pet-oriented interface and mutates a pet-type constant. In a child-monitoring context, this semantic mismatch can cause incorrect model selection, misclassification, or inappropriate downstream handling of sensitive footage, which is especially problematic because the system processes children's images and behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The user-facing argparse descriptions and help strings are written only in Chinese, which imposes a specific language for interaction. The file does not provide any alternate locale, language selection mechanism, or documented justification for the restriction.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI exposes --pet-type choices (cat, dog, other) while the surrounding documentation claims the tool performs child emotion/event recognition. This contradiction increases the risk of operator misuse, silent fallback to the wrong category, and misleading processing of children's surveillance data under an unrelated taxonomy.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2