Back to skill

Security audit

Driver Head-Pose Abnormality (Head-Down / Side-View) | 驾驶员头部姿态异常(低头/侧视)检测

Security checks for vulnerabilities and agentic risk

Overview

This skill analyzes driver media through a cloud service, but it also silently creates or reuses an identity and persists tokens for history/report access, which users should review before installing.

Install only if you are comfortable sending driver videos or media URLs to the configured lifeemergence.com cloud service and having reports tied to a silently managed local identity. Use it with explicit driver/employee consent, review local `data` identity/token state between users, and avoid broad history queries unless you intend to retrieve prior cloud-stored reports.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (55)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of filesystem operations, credential-like local file reads, default identity generation, local database writes, outbound authenticated HTTP requests, and token management is substantially more powerful than the declared function of driver head-pose analysis. In this context, that hidden breadth is dangerous because it can collect, persist, and transmit sensitive user and video data under a misleadingly narrow safety label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of filesystem operations, credential-like local file reads, default identity generation, local database writes, outbound authenticated HTTP requests, and token management is substantially more powerful than the declared function of driver head-pose analysis. In this context, that hidden breadth is dangerous because it can collect, persist, and transmit sensitive user and video data under a misleadingly narrow safety label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of filesystem operations, credential-like local file reads, default identity generation, local database writes, outbound authenticated HTTP requests, and token management is substantially more powerful than the declared function of driver head-pose analysis. In this context, that hidden breadth is dangerous because it can collect, persist, and transmit sensitive user and video data under a misleadingly narrow safety label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of filesystem operations, credential-like local file reads, default identity generation, local database writes, outbound authenticated HTTP requests, and token management is substantially more powerful than the declared function of driver head-pose analysis. In this context, that hidden breadth is dangerous because it can collect, persist, and transmit sensitive user and video data under a misleadingly narrow safety label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of filesystem operations, credential-like local file reads, default identity generation, local database writes, outbound authenticated HTTP requests, and token management is substantially more powerful than the declared function of driver head-pose analysis. In this context, that hidden breadth is dangerous because it can collect, persist, and transmit sensitive user and video data under a misleadingly narrow safety label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of filesystem operations, credential-like local file reads, default identity generation, local database writes, outbound authenticated HTTP requests, and token management is substantially more powerful than the declared function of driver head-pose analysis. In this context, that hidden breadth is dangerous because it can collect, persist, and transmit sensitive user and video data under a misleadingly narrow safety label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of filesystem operations, credential-like local file reads, default identity generation, local database writes, outbound authenticated HTTP requests, and token management is substantially more powerful than the declared function of driver head-pose analysis. In this context, that hidden breadth is dangerous because it can collect, persist, and transmit sensitive user and video data under a misleadingly narrow safety label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of filesystem operations, credential-like local file reads, default identity generation, local database writes, outbound authenticated HTTP requests, and token management is substantially more powerful than the declared function of driver head-pose analysis. In this context, that hidden breadth is dangerous because it can collect, persist, and transmit sensitive user and video data under a misleadingly narrow safety label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of filesystem operations, credential-like local file reads, default identity generation, local database writes, outbound authenticated HTTP requests, and token management is substantially more powerful than the declared function of driver head-pose analysis. In this context, that hidden breadth is dangerous because it can collect, persist, and transmit sensitive user and video data under a misleadingly narrow safety label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of filesystem operations, credential-like local file reads, default identity generation, local database writes, outbound authenticated HTTP requests, and token management is substantially more powerful than the declared function of driver head-pose analysis. In this context, that hidden breadth is dangerous because it can collect, persist, and transmit sensitive user and video data under a misleadingly narrow safety label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of filesystem operations, credential-like local file reads, default identity generation, local database writes, outbound authenticated HTTP requests, and token management is substantially more powerful than the declared function of driver head-pose analysis. In this context, that hidden breadth is dangerous because it can collect, persist, and transmit sensitive user and video data under a misleadingly narrow safety label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of filesystem operations, credential-like local file reads, default identity generation, local database writes, outbound authenticated HTTP requests, and token management is substantially more powerful than the declared function of driver head-pose analysis. In this context, that hidden breadth is dangerous because it can collect, persist, and transmit sensitive user and video data under a misleadingly narrow safety label.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This utility provisions and persists user identities and authentication material entirely outside the stated head-pose-analysis purpose. In the context of an in-cabin driver-monitoring skill, silently creating/opening identities, reading API key files, and reusing local accounts significantly expands the trust boundary and can enable unauthorized account linkage, credential misuse, and opaque backend access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The HTTP utility performs remote login/registration flows, injects tokens into requests, retries on authorization failure, and persists returned tokens/user records. For a skill advertised as local driver head-pose abnormality analysis, this is unrelated privileged behavior that creates covert external dependencies and a path for user tracking, account creation, and transmission of identity data to remote services.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises and instructs use of shell, network, filesystem, environment, and likely local state, but it does not declare any explicit tool scope or least-privilege boundaries. In a skill that uploads files, queries cloud history, and manages local identity/state, missing permission declarations increases the chance of unintended capability use and makes review and containment harder.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The default trigger is broad enough to invoke analysis whenever a DMS-like driver-face video is present, even without a clear request for this specific skill. In a surveillance/media-processing context, overly broad auto-triggering can cause unwanted processing and transmission of sensitive driver video.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest frames the skill as a head-pose analyzer, but the documented behavior also includes cloud history-report querying and report-link retrieval. That scope drift matters because users may not expect a safety-analysis tool to enumerate prior cloud-stored records tied to an identity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Automatic cloud API access for historical report lookup is not necessary for the stated purpose of analyzing a provided DMS video. In a privacy-sensitive driving context, unsolicited or implicit access to stored historical records broadens exposure of behavioral surveillance data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Broad historical-report trigger phrases like 'show all head-pose reports' and 'query distraction event list' can activate sensitive data retrieval without adequate scoping. This increases the chance of over-collection or disclosure of more historical driver data than the user intended.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Auto-creating or reusing a local default user identity for a driver-monitoring workflow is risky because it silently binds sensitive reports to an internal identity the user never supplied or reviewed. This can cause cross-session confusion, unauthorized record association, and privacy violations if multiple users share the environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description presents only real-time head-pose analysis, but the CLI also exposes a history-listing function keyed by user identity via show_analyze_list(open_id). This creates an undisclosed data-access surface for potentially sensitive driver monitoring records, and if identity resolution or authorization is weak elsewhere, it could enable unauthorized enumeration of another user's analysis history.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Multiple user-visible strings are hard-coded in Chinese, such as the analysis report headings and error/status messages. This imposes a specific language on users without opt-in or documented locale justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill accepts arbitrary HTTP/HTTPS URLs and forwards them to the downstream analysis service, which expands the input scope beyond the declared in-cabin DMS camera use case. This creates a capability mismatch and can enable analysis of unintended third-party or sensitive remote content, with privacy, policy, and potential backend-fetch abuse implications depending on how the service resolves the URL.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2