Back to skill

Security audit

Time-Lapse Album Custom Summarization Skill | 时光相册自定义浓缩分析技能

Security checks for vulnerabilities and agentic risk

Overview

The skill is a cloud video-analysis tool, but it silently manages identity and credentials and ships with plaintext private-network API endpoints, so it needs review before installation.

Install only if you are comfortable with uploaded media, identity values, historical reports, and reusable tokens being handled by this provider. The publisher should switch to trusted HTTPS production endpoints, remove the API-key-file identity fallback, require clear consent for uploads/history lookup, and protect or avoid persistent token storage before broad use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/util.py:414
Finding

Workspace API-key file content disclosed as an identity over plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: skills/smyx_common/scripts/util.py:414-420, 458-466, 550-561; skills/smyx_common/scripts/config.yaml:15; skills/smyx_common/scripts/config-dev.yaml:2-4
Vulnerability Type: Sensitive information disclosure over an unencrypted network connection
Risk Level: High

Vulnerable Code

python
@classmethod
def get_api_key_file_open_id(cls):
    """Read the internal identity value from workspace data/smyx-api-key.txt."""
    api_key_path = os.path.join(cls.get_workspace_data_dir(), "smyx-api-key.txt")
    try:
        if not os.path.exists(api_key_path):
            return None
        with open(api_key_path, "r", encoding="utf-8") as f:
            value = f.read().strip()
        return value or None
python
def resolve_current_open_id(cls, open_id=None, use_current=True):
    """Resolve and initialize the current open-id."""
    resolved_open_id = (open_id or "").strip() if isinstance(open_id, str) else open_id
    if not resolved_open_id and use_current:
        resolved_open_id = ConstantEnum.CURRENT__OPEN_ID or ConstantEnum.CURRENT__USER_NAME
    if not resolved_open_id:
        resolved_open_id = cls.get_api_key_file_open_id()
    if not resolved_open_id:
        resolved_open_id = cls.get_or_create_default_open_id()
python
def _get_or_create_user(username):
    _url = ApiEnum.BASE_URL_HEALTH + "/sys/phoneLogin"
    open_id = username
    _data = {
        "silent": 1,
        "register": 1,
        "openId": open_id,
        "mobile": username,
        "source": ConstantEnum.DEFAULT__SKILL_HUB_NAME
    }
    try:
        _response = requests.post(_url, json=_data)

The selected configuration environment is:

yaml
env: dev

Its effective endpoints are:

yaml
ApiEnum:
  base-url-open-api: "http://192.168.1.234:9601/smyx-open-api"
  base-url-open-h5: "http://192.168.1.234:4100
...[truncated 2275 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the fallback that reads identity information from smyx-api-key.txt.
  2. Store API credentials and user identifiers in separate files or credential-store entries with unambiguous names and schemas.
  3. Use an OS-backed credential store for API keys rather than a plaintext workspace file.
  4. Require HTTPS for authentication endpoints and reject any http:// destination before sending data.
  5. Replace the checked-in development environment with a production-safe default.
  6. Restrict remote destinations to an explicit allowlist of trusted hostnames; do not use mutable private-network addresses for authentication.
  7. Send only the minimum required identifier and do not duplicate it into both openId and mobile.
  8. Obtain explicit, informed consent before transmitting a locally stored identifier.
  9. Rotate any credentials that may already have been stored in smyx-api-key.txt and transmitted by this implementation.
  10. Add automated tests confirming that API-key file contents can never enter request bodies, query parameters, or logs.

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/util.py:576
Finding

Private media, bearer tokens, and user identifiers transmitted through plaintext HTTP endpoints

Content
View full analysis

Vulnerability Details

File Location: skills/smyx_analysis/scripts/skill.py:105-129; skills/smyx_common/scripts/util.py:576-646; skills/smyx_common/scripts/config.yaml:15; skills/smyx_common/scripts/config-dev.yaml:2-4
Vulnerability Type: Unencrypted transmission of sensitive media and authentication material
Risk Level: High

Vulnerable Code

The analysis implementation reads the complete local media file and prepares it for upload:

python
if (input_path.startswith("http://") or input_path.startswith("https://")):
    params.update({
        "videoUrl": input_path
    })
else:
    _validate_file(input_path)

    # Automatically detect MIME type
    mime_type, _ = mimetypes.guess_type(input_path)
    if mime_type is None:
        mime_type = 'application/octet-stream'

    # Read file contents
    with open(input_path, 'rb') as f:
        file_content = f.read()

    files = {
        'file': (os.path.basename(input_path), file_content, mime_type)
    }

The common request layer adds account credentials and an identity to outgoing requests:

python
headers.setdefault("X-Access-Token", ApiEnum.TOKEN)
headers.setdefault("X-Api-Key", ApiEnum.API_SECRET_KEY)
headers.setdefault("Authorization", ApiEnum.OPEN_TOKEN)

data = data or {}
params = params or {}
options = options or {}
ConstantEnum.CURRENT__TENTANT_CODE and data.setdefault(
    'tenantCode', ConstantEnum.CURRENT__TENTANT_CODE
)
ConstantEnum.DEFAULT__SKILL_HUB_NAME and data.setdefault(
    'skillHubName', ConstantEnum.DEFAULT__SKILL_HUB_NAME
)
ConstantEnum.DEFAULT__SKILL_PLATFORM_NAME and data.setdefault(
    'skillPlatform', ConstantEnum.DEFAULT__SKILL_PLATFORM_NAME
)
if current__user_name:
    data.setdefault('pnaUserName', current__user_name)

if bool(options.get("dataAsParams")) or bool(options.get("data_as_params")):
    params.update(data)

response = requests.request(
    met
...[truncated 2752 chars]
Remediation
View remediation

Remediation Suggestions

  1. Reject all non-HTTPS API endpoints in the request layer, including configuration overrides.
  2. Change the packaged default environment from dev to a production-safe configuration.
  3. Remove hard-coded private-IP service addresses from distributable artifacts.
  4. Permit connections only to an explicit allowlist of trusted HTTPS hostnames.
  5. Retain TLS certificate verification and consider certificate pinning where operationally appropriate.
  6. Use short-lived, narrowly scoped authorization tokens rather than long-lived reusable bearer tokens.
  7. Avoid sending multiple authentication mechanisms unless each is strictly required.
  8. Keep identity and tenant metadata out of query strings because URLs are commonly retained by proxies and access logs.
  9. Provide a clear disclosure that media is uploaded to a remote service and require user approval before the upload begins.
  10. Add integration tests that fail whenever media or authorization headers are sent to an HTTP URL.
  11. Revoke and rotate tokens used while the plaintext development configuration was active.

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smyx_common/scripts/dao.py:460
Finding

Reusable authentication tokens stored in a plaintext local database

Content
View full analysis

Vulnerability Details

File Location: skills/smyx_common/scripts/util.py:586-604; skills/smyx_common/scripts/dao.py:460-461
Vulnerability Type: Insecure storage of authentication credentials
Risk Level: Medium

Vulnerable Code

Tokens returned by the remote login service are copied into the local user model and saved:

python
if found_user:
    ApiEnum.TOKEN = found_user.token
    ApiEnum.OPEN_TOKEN = found_user.open_token
    current__user_name = found_user.username
if not ApiEnum.TOKEN or not ApiEnum.OPEN_TOKEN:
    new_current_user = _get_or_create_user(current__user_name)
    if new_current_user:
        ApiEnum.TOKEN = new_current_user.get("token")
        ApiEnum.OPEN_TOKEN = new_current_user.get("openToken")

        current_user_info = new_current_user.get("userInfo")
        if current_user_info:
            current_user_info["token"] = new_current_user.get("token")
            current_user_info["openToken"] = new_current_user.get(
                "openToken")
            user_model = User.load(current_user_info)

            user = user_dao.save(
                user_model
            )

The database model stores both values as ordinary string columns:

python
token = Column(String(500), comment="token")
open_token = Column(String(1000), comment="open token")

Technical Analysis

The authentication bootstrap persists the returned token and openToken directly in the local database. The reviewed code does not encrypt these fields, use an OS-backed secret store, or demonstrate restrictive database-file permissions.

Bearer tokens are equivalent to credentials for their validity period. Unlike password hashes, they must be recoverable for use, so storing them in ordinary database columns makes them immediately reusable by any process or user capable of reading the database.

Local caching can reduce repeated authentication calls, but persistent p ...[truncated 1289 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not persist access tokens unless persistence is essential.
  2. Prefer short-lived tokens retained only in process memory.
  3. If persistence is required, store tokens in an OS credential manager or encrypted secret store.
  4. Encrypt token values with a key that is not stored alongside the database.
  5. Apply restrictive owner-only permissions to the database and its containing directory.
  6. Use narrowly scoped tokens with short expiration periods and server-side rotation.
  7. Revoke cached credentials on logout, authorization failure, account changes, and Skill removal.
  8. Ensure backups, crash dumps, and diagnostic exports exclude token fields.
  9. Add automatic redaction so tokens cannot enter logs, exceptions, or serialized reports.
  10. Rotate previously persisted tokens after deploying protected storage.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (57)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of network/API communication, authentication management, identity generation/persistence, workspace discovery, file access, and local database interaction—without evidence of actual video summarization—represents a substantial hidden capability gap. In context, this is dangerous because a media-upload skill can become a conduit for data exfiltration, tracking, and unauthorized retention.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of network/API communication, authentication management, identity generation/persistence, workspace discovery, file access, and local database interaction—without evidence of actual video summarization—represents a substantial hidden capability gap. In context, this is dangerous because a media-upload skill can become a conduit for data exfiltration, tracking, and unauthorized retention.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of network/API communication, authentication management, identity generation/persistence, workspace discovery, file access, and local database interaction—without evidence of actual video summarization—represents a substantial hidden capability gap. In context, this is dangerous because a media-upload skill can become a conduit for data exfiltration, tracking, and unauthorized retention.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of network/API communication, authentication management, identity generation/persistence, workspace discovery, file access, and local database interaction—without evidence of actual video summarization—represents a substantial hidden capability gap. In context, this is dangerous because a media-upload skill can become a conduit for data exfiltration, tracking, and unauthorized retention.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of network/API communication, authentication management, identity generation/persistence, workspace discovery, file access, and local database interaction—without evidence of actual video summarization—represents a substantial hidden capability gap. In context, this is dangerous because a media-upload skill can become a conduit for data exfiltration, tracking, and unauthorized retention.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of network/API communication, authentication management, identity generation/persistence, workspace discovery, file access, and local database interaction—without evidence of actual video summarization—represents a substantial hidden capability gap. In context, this is dangerous because a media-upload skill can become a conduit for data exfiltration, tracking, and unauthorized retention.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of network/API communication, authentication management, identity generation/persistence, workspace discovery, file access, and local database interaction—without evidence of actual video summarization—represents a substantial hidden capability gap. In context, this is dangerous because a media-upload skill can become a conduit for data exfiltration, tracking, and unauthorized retention.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of network/API communication, authentication management, identity generation/persistence, workspace discovery, file access, and local database interaction—without evidence of actual video summarization—represents a substantial hidden capability gap. In context, this is dangerous because a media-upload skill can become a conduit for data exfiltration, tracking, and unauthorized retention.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of network/API communication, authentication management, identity generation/persistence, workspace discovery, file access, and local database interaction—without evidence of actual video summarization—represents a substantial hidden capability gap. In context, this is dangerous because a media-upload skill can become a conduit for data exfiltration, tracking, and unauthorized retention.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of network/API communication, authentication management, identity generation/persistence, workspace discovery, file access, and local database interaction—without evidence of actual video summarization—represents a substantial hidden capability gap. In context, this is dangerous because a media-upload skill can become a conduit for data exfiltration, tracking, and unauthorized retention.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of network/API communication, authentication management, identity generation/persistence, workspace discovery, file access, and local database interaction—without evidence of actual video summarization—represents a substantial hidden capability gap. In context, this is dangerous because a media-upload skill can become a conduit for data exfiltration, tracking, and unauthorized retention.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "custom-timelapse-analysis"
description: "Generates condensed album highlights based on specified keywords or targets. It extracts specific target segments from long videos and compiles them into an exciting summary. | 时光相册自定义浓缩分析技能,基于指定关键词/目标生成时光相册浓缩集锦,从长视频中提取特定目标片段,整理生成精彩汇总"
version: "1.0.16"
license: "MIT-0"
---

# ⏱️ Time-Lapse Album Custom Summarization Skill | 时光相册自定义浓缩分析技能
> **智能分析中枢** · 图片/视频智能分析 · 结构化报告 · 历史报告云端查询

-

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation materially differs from the stated skill purpose. Instead of performing timelapse highlight generation or segment extraction, it submits content to a generic analysis backend, polls for report completion, formats arbitrary analysis output, and exposes report export links. This capability mismatch is dangerous because users may provide sensitive video content under false expectations, while the skill can process or disclose unrelated analysis data through broader backend functions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The HTTP helper automatically performs phone-login/registration, fetches tokens, and persists them for later reuse before making requests. This expands the skill from media processing into covert account provisioning and authenticated outbound activity, which is especially risky because it happens transparently in a low-level utility likely used across the skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises and instructs use of shell, network, file read/write, and environment-backed behavior but does not declare any explicit tool scope or permissions boundaries. In an agent environment, this weakens least-privilege controls and makes it easier for the skill to invoke sensitive capabilities beyond what users would reasonably expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad enough to match common requests around analysis, report lookup, and video-related keywords. Overbroad auto-triggering is risky because it can cause this skill to run in situations where users did not intend cloud processing, local file saving, or history retrieval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill includes cloud historical report querying beyond its advertised summarization role. This expands the data-access surface from processing a provided file to retrieving past user-linked records, which raises privacy and authorization concerns if not separately disclosed and permissioned.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill states that uploaded attachments are automatically saved locally, but the description does not clearly warn users about this retention behavior up front. For a media-focused skill handling potentially sensitive personal videos and images, undisclosed local persistence materially increases privacy risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation adds automatic internal identity reuse/creation that is outside the core stated purpose of video summarization. Silent identity creation and reuse can enable tracking, cross-session correlation, and hidden account linkage without meaningful user awareness or consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code hard-codes the command description, help text, and status/error messages in Chinese, which imposes a specific language on all users. The file does not offer an opt-in language choice or document that the tool is intentionally region-specific, so it conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The method returns a fixed Chinese-language user-facing string, which imposes a specific language on all users. The file does not indicate any opt-in, locale selection, or justification for a Chinese-only experience.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The code reads the entire local file and prepares it for upload to a remote analysis service without any visible consent, warning, or data-minimization controls in this component. For a skill that may handle personal videos, silent transfer of full local media can expose sensitive content, location cues, bystanders, or other private information to external systems.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill exposes a report-history listing function unrelated to the advertised purpose of generating custom timelapse highlights. In a least-privilege model, a media-processing skill should not also enumerate prior analysis records, because this can reveal metadata, prior outputs, or report identifiers from unrelated user activity if access controls are weak upstream.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2