Back to skill

Security audit

Contactless Health Risk Screening Tool | 非接触式健康风险检测分析工具

Security checks for vulnerabilities and agentic risk

Overview

The skill’s health-screening purpose is coherent, but it handles facial and health-related data with insecure defaults, silent account setup, cloud history access, and local token persistence that users should review before installing.

Review this skill carefully before installing. It is intended to send facial images or videos to a remote service and query cloud-stored health reports, but the package also silently creates or reuses an identity, stores tokens locally, and currently defaults to development HTTP endpoints. Do not use it with real biometric or health data unless the publisher fixes HTTPS-only configuration, documents retention and account handling, secures local credentials, and adds clear user confirmation for history access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/config.yaml:15
Finding

Facial biometric data and authentication credentials transmitted over plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smyx_common/scripts/dao.py:449
Finding

Reusable authentication tokens and identity records stored unencrypted in SQLite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smyx_common/scripts/util.py:35
Finding

Low-level HTTP debugging can disclose tokens and sensitive request data

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skills/smyx_analysis/requirements.txt:3
Finding

Incorrect YAML dependency name creates dependency-confusion risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (59)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "contactless-health-risk-detection-analysis"
description: "Combines frontal facial image capture with multimodal physiological feature analysis to provide early risk screening and alerts for chronic and acute conditions such as heart attack, stroke, hypertension, and hyperlipidemia. | 非接触式健康风险识别技能,通过正面人像采集结合多模态生理特征分析,提供心梗、脑梗、高血压、高血脂等慢病急症早期风险筛查预警"
version: "1.0.15"
license: "MIT-0"
---

# 🩺 Contactless Health Risk Screening Tool | 非接触式健康风险检测分析工具

> **智能健康/识别分析中枢** · �

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill handles facial images, videos, inferred health information, and cloud API transmission, yet the description does not clearly warn users that this sensitive biometric and medical-adjacent data is sent to remote services. In this context, lack of transparent privacy disclosure is a significant vulnerability because users cannot meaningfully consent to highly sensitive processing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill performs frontal face capture and multimodal physiological feature analysis for health-risk screening, but the code exposes a generic analyze_video flow and a show_analyze_list history-listing capability with no health-specific processing, facial capture handling, or physiological analysis logic. The CLI is documented as a "视频分析工具" and accepts arbitrary local or remote video inputs, which materially differs from the stated medical screening purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The User model stores identity attributes and authentication-like secrets such as token and open_token, which are not justified by the stated health-risk detection purpose. In a health-oriented skill, collecting and persisting identifiers plus tokens creates a high-value privacy and account-compromise target, especially if stored locally without explicit safeguards shown here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The HTTP utility automatically resolves an internal identity, performs silent remote account creation/login via /sys/phoneLogin, and persists returned token material locally. That behavior is unrelated to the stated health-risk screening purpose and creates undisclosed identity provisioning and credential handling, which can transmit and bind user context to a backend without informed consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares operational behaviors that imply shell, filesystem, network, and environment access, but it does not declare any explicit tool scope or permissions boundaries. That creates unnecessary ambiguity for reviewers and increases the risk that an agent may run with broader capabilities than users expect, especially given the handling of sensitive medical and facial data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The history-report trigger phrases are broad enough that ordinary conversation about reports could invoke cloud history retrieval automatically. Because the reports are health-related and identity-linked, accidental triggering can expose sensitive historical data with insufficient user confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill automatically saves uploaded videos or images as local files, but this persistence is not clearly disclosed. Undisclosed local storage of biometric media increases the risk of data retention, unauthorized access, and accidental reuse beyond the user's expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The instruction mandates that report output be automatically converted to a specific Markdown presentation format, and the document is strongly oriented around fixed bilingual content without stating that users may choose their preferred output language or locale. This can constitute a language/locale policy issue when the skill imposes a preset presentation style or language behavior without opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill exposes a history-listing capability via show_analyze_list() and the --list flag, which goes beyond the stated purpose of single image/video health-risk screening. In a health context, listing prior analyses can expose sensitive medical inference history and broaden access to personal data without clear authorization checks in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code presents the tool description and help text entirely in Chinese, which imposes a specific language on users without any opt-in or alternative locale support. The stated policy flags language or locale constraints unless the skill offers a choice or clearly documents a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code resolves an internal user identity with OpenIdUtil.resolve_current_open_id(...) even though identity-management is not part of the declared skill function. In a medical screening workflow, implicit identity resolution can silently bind scans and history to an internal account, increasing privacy risk and enabling unauthorized access or cross-user data exposure if the utility defaults are unsafe.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing string returned by the skill is hard-coded in Chinese: "📊 非接触健康风险识别分析结构化结果". This indicates a fixed language choice with no visible option for user language preference or justification for a region-specific constraint, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2