Back to skill

Security audit

Egg Incubation Monitoring (Turtle/Snake) | 孵化箱内龟蛋/蛇蛋发育监测

Security checks for vulnerabilities and agentic risk

Overview

The skill is a cloud-based egg incubation media analyzer, but it silently creates/uses account identity, stores tokens locally, and sends media or URLs to a remote service with limited user control.

Install only if you are comfortable with egg images/videos or supplied URLs being processed by the Life Emergence cloud service, with the skill automatically creating or reusing an internal account identity and storing local token/history data. Avoid giving it private/internal URLs or sensitive media unless that cloud processing and persistence are acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (55)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, automatic open-id generation, persistence, auto-registration/login, filesystem discovery, and polling infrastructure materially exceed the claimed incubator image-analysis scope. The combination of hidden identity lifecycle management and remote service use is dangerous because it can create opaque user tracking and data-transfer channels without meaningful user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, automatic open-id generation, persistence, auto-registration/login, filesystem discovery, and polling infrastructure materially exceed the claimed incubator image-analysis scope. The combination of hidden identity lifecycle management and remote service use is dangerous because it can create opaque user tracking and data-transfer channels without meaningful user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, automatic open-id generation, persistence, auto-registration/login, filesystem discovery, and polling infrastructure materially exceed the claimed incubator image-analysis scope. The combination of hidden identity lifecycle management and remote service use is dangerous because it can create opaque user tracking and data-transfer channels without meaningful user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, automatic open-id generation, persistence, auto-registration/login, filesystem discovery, and polling infrastructure materially exceed the claimed incubator image-analysis scope. The combination of hidden identity lifecycle management and remote service use is dangerous because it can create opaque user tracking and data-transfer channels without meaningful user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, automatic open-id generation, persistence, auto-registration/login, filesystem discovery, and polling infrastructure materially exceed the claimed incubator image-analysis scope. The combination of hidden identity lifecycle management and remote service use is dangerous because it can create opaque user tracking and data-transfer channels without meaningful user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, automatic open-id generation, persistence, auto-registration/login, filesystem discovery, and polling infrastructure materially exceed the claimed incubator image-analysis scope. The combination of hidden identity lifecycle management and remote service use is dangerous because it can create opaque user tracking and data-transfer channels without meaningful user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, automatic open-id generation, persistence, auto-registration/login, filesystem discovery, and polling infrastructure materially exceed the claimed incubator image-analysis scope. The combination of hidden identity lifecycle management and remote service use is dangerous because it can create opaque user tracking and data-transfer channels without meaningful user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, automatic open-id generation, persistence, auto-registration/login, filesystem discovery, and polling infrastructure materially exceed the claimed incubator image-analysis scope. The combination of hidden identity lifecycle management and remote service use is dangerous because it can create opaque user tracking and data-transfer channels without meaningful user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, automatic open-id generation, persistence, auto-registration/login, filesystem discovery, and polling infrastructure materially exceed the claimed incubator image-analysis scope. The combination of hidden identity lifecycle management and remote service use is dangerous because it can create opaque user tracking and data-transfer channels without meaningful user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, automatic open-id generation, persistence, auto-registration/login, filesystem discovery, and polling infrastructure materially exceed the claimed incubator image-analysis scope. The combination of hidden identity lifecycle management and remote service use is dangerous because it can create opaque user tracking and data-transfer channels without meaningful user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, automatic open-id generation, persistence, auto-registration/login, filesystem discovery, and polling infrastructure materially exceed the claimed incubator image-analysis scope. The combination of hidden identity lifecycle management and remote service use is dangerous because it can create opaque user tracking and data-transfer channels without meaningful user awareness.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill’s implemented input handling materially exceeds its stated purpose: instead of periodic fixed-camera egg surface image analysis, it accepts arbitrary local files and remote URLs and labels URL input as video content. This broadens the attack and privacy surface by enabling processing of unrelated media and external sources without clear restriction, which is dangerous in a narrowly scoped monitoring skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes periodic analysis of egg surface images from a fixed incubator camera to detect shell color changes, blood streaks, and embryo silhouettes, but this file is built around analyzing arbitrary MP4 videos or remote video URLs and listing prior video analyses. That is a substantial semantic mismatch in modality and workflow, indicating the implemented behavior is a generic video-analysis client rather than an egg-incubation image-monitoring tool.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This shared utility file contains account identity resolution, workspace identity harvesting, local user persistence, token caching, remote authentication, and automatic request decoration that are unrelated to incubator image analysis. In the context of a camera-based egg monitoring skill, bundling hidden identity and login flows substantially increases the attack surface and enables covert user/account operations under the guise of an unrelated function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code silently calls an external health-service login endpoint with register=1 and silent=1, meaning it can create or log in accounts without clear user awareness. For an egg-incubation monitoring skill, this behavior is unjustified and dangerous because it transmits identity-derived data to a remote service and may bind the local environment to unintended external accounts.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares powerful capabilities in practice (shell, network, filesystem, environment access) but does not explicitly scope or constrain them in the manifest. That creates an overprivileged execution surface where reviewers and runtimes cannot easily enforce least privilege, increasing the chance of unintended command execution, data access, or outbound transmission.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

A broad default trigger can activate the skill for any uploaded egg-related image or video, even when the user did not clearly request this workflow. That increases the chance of unintended file handling, outbound transmission, or persistent record creation based on ambiguous context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states that uploaded attachments are automatically saved locally, but it does not present a clear user-facing warning about storage, retention, or subsequent transmission. Silent persistence of user media creates privacy and compliance risk, especially for image/video content and when paired with history or cloud-report features.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script exposes a history-listing feature keyed by open_id, which is outside the stated egg image analysis purpose and creates a privacy/data exposure risk if a caller can influence identity selection. Because --open-id is accepted and then used to resolve the current identity before listing, an attacker may be able to retrieve another user's analysis history if downstream authorization is weak or absent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Hidden identity resolution without user-facing disclosure is a security and privacy concern because the tool silently binds actions to a user context and may fetch or expose account-scoped data. In this file, that concern is amplified by the simultaneous support for a hidden open_id parameter and a history-listing feature, increasing the chance of unintended cross-user access or opaque data handling.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Multiple returned messages are fixed Chinese strings, such as the report header and export-link text, with no indication that the user can choose another language. This is a natural-language policy issue because the skill imposes a locale/language choice rather than offering opt-in or configuration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Exceptions and status text such as file validation errors are written only in Chinese, which imposes a single language on all users. There is no visible mechanism in this file for locale selection, fallback, or explicit user consent to that language constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code accepts arbitrary http/https URLs and forwards them to the backend analysis service as videoUrl with no allowlist, hostname validation, or scheme narrowing beyond basic prefix checks. If the backend fetches these URLs, this can enable SSRF-style behavior, access to internal resources, or unintended retrieval of attacker-controlled content through a capability not justified by the fixed-camera incubation use case.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2