Back to skill

Security audit

Child Poor Posture (Hunchback / Head Tilt) Real-Time Reminder | 儿童坐姿不良(驼背/歪头)实时提醒

Security checks for vulnerabilities and agentic risk

Overview

This skill performs the advertised child posture analysis, but it sends sensitive child video/report data to cloud APIs and silently creates or reuses persistent user identities and tokens.

Review this skill before installing in any child, home, or school setting. It should only be used with guardian consent and with clear answers from the publisher about where video is processed, how reports and tokens are stored, who can access report links, how data is deleted, and how identity/account binding is protected.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/smyx_child_poor_posture_detection_analysis.py:47
Finding

Arbitrary identity impersonation through a hidden CLI parameter

Content
View full analysis

Vulnerability Details

File Location: scripts/smyx_child_poor_posture_detection_analysis.py:47,58; skills/smyx_common/scripts/util.py:459-470,551-563,578-612
Vulnerability Type: Authentication bypass and unauthorized account access
Risk Level: High

Vulnerable Code

python
# scripts/smyx_child_poor_posture_detection_analysis.py
parser.add_argument("--open-id", required=False, help=argparse.SUPPRESS)

# Initialize the internal user identity.
OpenIdUtil.resolve_current_open_id(
    args.open_id,
    use_current=bool(args.open_id)
)
python
# skills/smyx_common/scripts/util.py
resolved_open_id = (open_id or "").strip() if isinstance(open_id, str) else open_id
if not resolved_open_id and use_current:
    resolved_open_id = ConstantEnum.CURRENT__OPEN_ID or ConstantEnum.CURRENT__USER_NAME
if not resolved_open_id:
    resolved_open_id = cls.get_api_key_file_open_id()
if not resolved_open_id:
    resolved_open_id = cls.get_or_create_default_open_id()

ConstantEnum.CURRENT__OPEN_ID = resolved_open_id
if not ConstantEnum.CURRENT__USER_NAME:
    ConstantEnum.CURRENT__USER_NAME = resolved_open_id
return resolved_open_id
python
# skills/smyx_common/scripts/util.py
_url = ApiEnum.BASE_URL_HEALTH + "/sys/phoneLogin"
open_id = username
_data = {
    "silent": 1,
    "register": 1,
    "openId": open_id,
    "mobile": username,
    "source": ConstantEnum.DEFAULT__SKILL_HUB_NAME
}
_response = requests.post(_url, json=_data)
python
# skills/smyx_common/scripts/util.py
new_current_user = _get_or_create_user(current__user_name)
if new_current_user:
    ApiEnum.TOKEN = new_current_user.get("token")
    ApiEnum.OPEN_TOKEN = new_current_user.get("openToken")

headers.setdefault("X-Access-Token", ApiEnum.TOKEN)
headers.setdefault("X-Api-Key", ApiEnum.API_SECRET_KEY)
headers.setdefault("Authorization", ApiEnum.OPEN_TOKEN)

Technical Analysis

The entry point exposes a hidden --open-id argument and passes its value directly into ` ...[truncated 2895 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove caller-controlled identity selection

    • Delete the public or hidden --open-id argument from the ordinary Skill entry point.
    • Do not treat argument suppression as an access-control mechanism.
  2. Use a trusted identity channel

    • Accept identity only from an authenticated runtime integration.
    • Bind the supplied identity to the invoking principal through a signed assertion, verified session, or mutually authenticated service channel.
    • Maintain an explicit allowlist of trusted identity sources.
  3. Require proof of account ownership

    • Do not authenticate by submitting only openId or mobile.
    • Require a server-verifiable credential, signed nonce, authorization code, or equivalent challenge-response mechanism.
    • Disable identifier-only silent registration and login for this workflow.
  4. Enforce authorization server-side

    • Ensure history and report endpoints derive tenant and user scope from verified token claims rather than caller-submitted fields such as pnaUserName.
    • Reject mismatches between authenticated token claims and requested account identifiers.
  5. Protect locally cached credentials

    • Store tokens in an operating-system credential store or encrypted secret store rather than ordinary SQLite fields.
    • Apply restrictive file permissions to any unavoidable local credential database.
    • Expire and rotate tokens already issued through the identifier-only flow.
  6. Separate default-user behavior from real accounts

    • Use a narrowly scoped anonymous or device identity when no authenticated user exists.
    • Prevent generated default identities from accessing records belonging to other users.
    • Require explicit authenticated account linking before historical reports can be queried.
  7. Add security tests

    • Verify that arbitrary --open-id values cannot produce credentials.
    • Test that one identity cannot list, fetch, or create records in anothe ...[truncated 147 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (64)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to use external authenticated APIs, local credential files, filesystem workspace creation, local user/account creation, and identity resolution despite being marketed as a posture reminder tool. This is especially dangerous because it combines secrets handling, remote transfer, and child-related media/records under a misleadingly simple description, increasing the chance of over-trust and under-review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to use external authenticated APIs, local credential files, filesystem workspace creation, local user/account creation, and identity resolution despite being marketed as a posture reminder tool. This is especially dangerous because it combines secrets handling, remote transfer, and child-related media/records under a misleadingly simple description, increasing the chance of over-trust and under-review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to use external authenticated APIs, local credential files, filesystem workspace creation, local user/account creation, and identity resolution despite being marketed as a posture reminder tool. This is especially dangerous because it combines secrets handling, remote transfer, and child-related media/records under a misleadingly simple description, increasing the chance of over-trust and under-review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to use external authenticated APIs, local credential files, filesystem workspace creation, local user/account creation, and identity resolution despite being marketed as a posture reminder tool. This is especially dangerous because it combines secrets handling, remote transfer, and child-related media/records under a misleadingly simple description, increasing the chance of over-trust and under-review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to use external authenticated APIs, local credential files, filesystem workspace creation, local user/account creation, and identity resolution despite being marketed as a posture reminder tool. This is especially dangerous because it combines secrets handling, remote transfer, and child-related media/records under a misleadingly simple description, increasing the chance of over-trust and under-review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to use external authenticated APIs, local credential files, filesystem workspace creation, local user/account creation, and identity resolution despite being marketed as a posture reminder tool. This is especially dangerous because it combines secrets handling, remote transfer, and child-related media/records under a misleadingly simple description, increasing the chance of over-trust and under-review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to use external authenticated APIs, local credential files, filesystem workspace creation, local user/account creation, and identity resolution despite being marketed as a posture reminder tool. This is especially dangerous because it combines secrets handling, remote transfer, and child-related media/records under a misleadingly simple description, increasing the chance of over-trust and under-review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to use external authenticated APIs, local credential files, filesystem workspace creation, local user/account creation, and identity resolution despite being marketed as a posture reminder tool. This is especially dangerous because it combines secrets handling, remote transfer, and child-related media/records under a misleadingly simple description, increasing the chance of over-trust and under-review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to use external authenticated APIs, local credential files, filesystem workspace creation, local user/account creation, and identity resolution despite being marketed as a posture reminder tool. This is especially dangerous because it combines secrets handling, remote transfer, and child-related media/records under a misleadingly simple description, increasing the chance of over-trust and under-review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to use external authenticated APIs, local credential files, filesystem workspace creation, local user/account creation, and identity resolution despite being marketed as a posture reminder tool. This is especially dangerous because it combines secrets handling, remote transfer, and child-related media/records under a misleadingly simple description, increasing the chance of over-trust and under-review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to use external authenticated APIs, local credential files, filesystem workspace creation, local user/account creation, and identity resolution despite being marketed as a posture reminder tool. This is especially dangerous because it combines secrets handling, remote transfer, and child-related media/records under a misleadingly simple description, increasing the chance of over-trust and under-review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to use external authenticated APIs, local credential files, filesystem workspace creation, local user/account creation, and identity resolution despite being marketed as a posture reminder tool. This is especially dangerous because it combines secrets handling, remote transfer, and child-related media/records under a misleadingly simple description, increasing the chance of over-trust and under-review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to use external authenticated APIs, local credential files, filesystem workspace creation, local user/account creation, and identity resolution despite being marketed as a posture reminder tool. This is especially dangerous because it combines secrets handling, remote transfer, and child-related media/records under a misleadingly simple description, increasing the chance of over-trust and under-review.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-child-poor-posture-detection-analysis"
description: "Using the camera built into a smart desk lamp or mounted above the desk, the system analyzes the child's sitting-posture video in real time, detecting spinal curvature angle (estimated Cobb angle) and head tilt angle. | 通过智能台灯内置摄像头或书桌上方摄像头,实时分析儿童学习时的坐姿视频,检测脊柱弯曲角度(Cobb角估算)以及头部倾斜度(侧倾角)。当驼背(Cobb角>10°)或歪头(头部侧倾角>15°)持续时间超过预设阈值(如5秒)时,触发语音提醒(如'请坐直'、'头抬正'),帮助儿童�

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes cloud report queries and report pushes for children's video-derived data without a prominent warning that media and results may be transmitted to and stored by external services. Because the content concerns minors in home or school settings, insufficient disclosure materially elevates privacy, compliance, and trust risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill claims to perform child-posture monitoring, but it accepts a pet-related classification parameter and forwards the input to a generic skill.get_output_analysis() path without any visible posture-specific validation or routing. In a child video analysis context, this mismatch is dangerous because it can cause sensitive camera footage of children to be processed by the wrong backend logic, violating data-handling expectations and potentially sending data to unintended models or services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code automatically resolves, creates, and persists default user identities for API usage, including reading from local files and generating fallback usernames. For a child posture-detection skill that should plausibly operate locally on video, this introduces unnecessary identity management and persistent tracking capability that could be used to associate device activity with a durable user profile.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This shared utility performs remote account bootstrap/login, token handling, and payment-upgrade response flows that are unrelated to the declared child posture-analysis purpose of the skill. In the context of a camera-based child-monitoring skill, hidden network identity provisioning and monetization logic materially increases privacy and trust risk because it can transmit identifiers and enable backend coupling without clear necessity or user consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares no explicit tool permissions even though the documentation instructs use of shell execution, filesystem access, network access, environment usage, and local file writes. This creates an over-privileged and under-specified execution model where a host agent may permit sensitive capabilities without clear user-visible scoping or review.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill frames itself as real-time local monitoring but also defines cloud historical report querying and report-link retrieval as normal behavior. This discrepancy is risky because it obscures data retention and external storage of minors' posture-derived records, which changes the privacy impact substantially.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented input/output scope expands beyond the manifest to include local files, network URLs, structured reports, and report links. Expanded I/O increases attack surface and privacy exposure, particularly through remote URL ingestion and generation of shareable report artifacts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Parent report pushing and cloud report management are materially broader than simple posture reminders and involve transmission and retention of child-derived data. In this context, undeclared family-facing distribution of analysis results creates heightened privacy and consent risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The AI role instruction is written as a fixed directive in Chinese and does not provide any language-choice or opt-in mechanism, while the rest of the document is bilingual. This can violate language/locale policy when the skill is used by users expecting another language but the skill behavior is not explicitly configurable.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The default trigger condition is broad enough to activate on generic posture-analysis requests whenever a video or URL is supplied. Over-broad auto-triggering is risky because it may cause unintended processing or upload of sensitive children's media without a clear, intentional user request for this specific skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatic creation and reuse of a default local user identity is not necessary for simple posture analysis and introduces silent identity persistence. That can cause cross-session data mixing, unauthorized history association, and opaque handling of child-related records without informed consent.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2