T09 · Insecure Skill Coding Practices
- Location
skills/smyx_common/scripts/config.yaml:15- Finding
Facial biometric data and authentication credentials transmitted over plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s health-screening purpose is coherent, but it handles facial and health-related data with insecure defaults, silent account setup, cloud history access, and local token persistence that users should review before installing.
Review this skill carefully before installing. It is intended to send facial images or videos to a remote service and query cloud-stored health reports, but the package also silently creates or reuses an identity, stores tokens locally, and currently defaults to development HTTP endpoints. Do not use it with real biometric or health data unless the publisher fixes HTTPS-only configuration, documents retention and account handling, secures local credentials, and adds clear user confirmation for history access.
skills/smyx_common/scripts/config.yaml:15Facial biometric data and authentication credentials transmitted over plaintext HTTP
skills/smyx_common/scripts/dao.py:449Reusable authentication tokens and identity records stored unencrypted in SQLite
skills/smyx_common/scripts/util.py:35Low-level HTTP debugging can disclose tokens and sensitive request data
skills/smyx_analysis/requirements.txt:3Incorrect YAML dependency name creates dependency-confusion risk
This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.
This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.
This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.
This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.
This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.
This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.
This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.
This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.
This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.
This finding indicates the skill performs broad local and remote identity management, filesystem access, environment inspection, API-key file reads, registration/login, token handling, and generic authenticated backend communication while presenting itself as a narrowly scoped health-screening tool. That is dangerous because it obscures extensive privileged operations and account-linked data flows behind a medical facade, increasing privacy and abuse risk.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
---
name: "contactless-health-risk-detection-analysis"
description: "Combines frontal facial image capture with multimodal physiological feature analysis to provide early risk screening and alerts for chronic and acute conditions such as heart attack, stroke, hypertension, and hyperlipidemia. | 非接触式健康风险识别技能,通过正面人像采集结合多模态生理特征分析,提供心梗、脑梗、高血压、高血脂等慢病急症早期风险筛查预警"
version: "1.0.15"
license: "MIT-0"
---
# 🩺 Contactless Health Risk Screening Tool | 非接触式健康风险检测分析工具
> **智能健康/识别分析中枢** · �
The skill handles facial images, videos, inferred health information, and cloud API transmission, yet the description does not clearly warn users that this sensitive biometric and medical-adjacent data is sent to remote services. In this context, lack of transparent privacy disclosure is a significant vulnerability because users cannot meaningfully consent to highly sensitive processing.
The manifest says the skill performs frontal face capture and multimodal physiological feature analysis for health-risk screening, but the code exposes a generic analyze_video flow and a show_analyze_list history-listing capability with no health-specific processing, facial capture handling, or physiological analysis logic. The CLI is documented as a "视频分析工具" and accepts arbitrary local or remote video inputs, which materially differs from the stated medical screening purpose.
The User model stores identity attributes and authentication-like secrets such as token and open_token, which are not justified by the stated health-risk detection purpose. In a health-oriented skill, collecting and persisting identifiers plus tokens creates a high-value privacy and account-compromise target, especially if stored locally without explicit safeguards shown here.
The HTTP utility automatically resolves an internal identity, performs silent remote account creation/login via /sys/phoneLogin, and persists returned token material locally. That behavior is unrelated to the stated health-risk screening purpose and creates undisclosed identity provisioning and credential handling, which can transmit and bind user context to a backend without informed consent.
The skill declares operational behaviors that imply shell, filesystem, network, and environment access, but it does not declare any explicit tool scope or permissions boundaries. That creates unnecessary ambiguity for reviewers and increases the risk that an agent may run with broader capabilities than users expect, especially given the handling of sensitive medical and facial data.
The history-report trigger phrases are broad enough that ordinary conversation about reports could invoke cloud history retrieval automatically. Because the reports are health-related and identity-linked, accidental triggering can expose sensitive historical data with insufficient user confirmation.
The skill automatically saves uploaded videos or images as local files, but this persistence is not clearly disclosed. Undisclosed local storage of biometric media increases the risk of data retention, unauthorized access, and accidental reuse beyond the user's expectations.
The instruction mandates that report output be automatically converted to a specific Markdown presentation format, and the document is strongly oriented around fixed bilingual content without stating that users may choose their preferred output language or locale. This can constitute a language/locale policy issue when the skill imposes a preset presentation style or language behavior without opt-in.
The skill exposes a history-listing capability via show_analyze_list() and the --list flag, which goes beyond the stated purpose of single image/video health-risk screening. In a health context, listing prior analyses can expose sensitive medical inference history and broaden access to personal data without clear authorization checks in this file.
This code presents the tool description and help text entirely in Chinese, which imposes a specific language on users without any opt-in or alternative locale support. The stated policy flags language or locale constraints unless the skill offers a choice or clearly documents a justified region-specific limitation.
The code resolves an internal user identity with OpenIdUtil.resolve_current_open_id(...) even though identity-management is not part of the declared skill function. In a medical screening workflow, implicit identity resolution can silently bind scans and history to an internal account, increasing privacy risk and enabling unauthorized access or cross-user data exposure if the utility defaults are unsafe.
The user-facing string returned by the skill is hard-coded in Chinese: "📊 非接触健康风险识别分析结构化结果". This indicates a fixed language choice with no visible option for user language preference or justification for a region-specific constraint, which matches the language/locale policy violation category.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)
result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
dict) else result_json
if result_json_common_ai_response:
result_json = result_json_common_ai_response
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)
result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
dict) else result_json
if result_json_common_ai_response:
result_json = result_json_common_ai_response
Detected: suspicious.install_untrusted_source