Back to skill

Security audit

Infant Blanket Kick Detection | 老年人夜间离床时长与徘徊识别

Security checks for vulnerabilities and agentic risk

Overview

This skill handles very sensitive elder bedroom monitoring videos through a remote service and silently manages a reusable local identity, while its artifacts overstate continuous monitoring and alerting capabilities.

Review this skill carefully before installing. It should only be used when the monitored person or authorized representative has consented, and when you are comfortable sending elder bedroom or hallway monitoring footage, video URLs, identity-linked report data, and reusable service tokens to the configured remote provider. Do not rely on it as a standalone emergency or continuous safety-monitoring system unless the publisher separately proves the live monitoring, alerting, retention, authorization, and deletion controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The manifest describes a safety-critical elderly monitoring and alerting system, but the observed behavior is generic backend/API wrapping rather than actual camera-based monitoring or alerting logic. This mismatch is dangerous because users may rely on the skill for real-world elder safety, while the implementation may silently fail to provide the claimed protections or may process unrelated data flows under misleading pretenses.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The manifest describes a safety-critical elderly monitoring and alerting system, but the observed behavior is generic backend/API wrapping rather than actual camera-based monitoring or alerting logic. This mismatch is dangerous because users may rely on the skill for real-world elder safety, while the implementation may silently fail to provide the claimed protections or may process unrelated data flows under misleading pretenses.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The manifest describes a safety-critical elderly monitoring and alerting system, but the observed behavior is generic backend/API wrapping rather than actual camera-based monitoring or alerting logic. This mismatch is dangerous because users may rely on the skill for real-world elder safety, while the implementation may silently fail to provide the claimed protections or may process unrelated data flows under misleading pretenses.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The manifest describes a safety-critical elderly monitoring and alerting system, but the observed behavior is generic backend/API wrapping rather than actual camera-based monitoring or alerting logic. This mismatch is dangerous because users may rely on the skill for real-world elder safety, while the implementation may silently fail to provide the claimed protections or may process unrelated data flows under misleading pretenses.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest describes a safety-critical elderly monitoring and alerting system, but the observed behavior is generic backend/API wrapping rather than actual camera-based monitoring or alerting logic. This mismatch is dangerous because users may rely on the skill for real-world elder safety, while the implementation may silently fail to provide the claimed protections or may process unrelated data flows under misleading pretenses.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest describes a safety-critical elderly monitoring and alerting system, but the observed behavior is generic backend/API wrapping rather than actual camera-based monitoring or alerting logic. This mismatch is dangerous because users may rely on the skill for real-world elder safety, while the implementation may silently fail to provide the claimed protections or may process unrelated data flows under misleading pretenses.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest describes a safety-critical elderly monitoring and alerting system, but the observed behavior is generic backend/API wrapping rather than actual camera-based monitoring or alerting logic. This mismatch is dangerous because users may rely on the skill for real-world elder safety, while the implementation may silently fail to provide the claimed protections or may process unrelated data flows under misleading pretenses.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest describes a safety-critical elderly monitoring and alerting system, but the observed behavior is generic backend/API wrapping rather than actual camera-based monitoring or alerting logic. This mismatch is dangerous because users may rely on the skill for real-world elder safety, while the implementation may silently fail to provide the claimed protections or may process unrelated data flows under misleading pretenses.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest describes a safety-critical elderly monitoring and alerting system, but the observed behavior is generic backend/API wrapping rather than actual camera-based monitoring or alerting logic. This mismatch is dangerous because users may rely on the skill for real-world elder safety, while the implementation may silently fail to provide the claimed protections or may process unrelated data flows under misleading pretenses.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest describes a safety-critical elderly monitoring and alerting system, but the observed behavior is generic backend/API wrapping rather than actual camera-based monitoring or alerting logic. This mismatch is dangerous because users may rely on the skill for real-world elder safety, while the implementation may silently fail to provide the claimed protections or may process unrelated data flows under misleading pretenses.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest describes a safety-critical elderly monitoring and alerting system, but the observed behavior is generic backend/API wrapping rather than actual camera-based monitoring or alerting logic. This mismatch is dangerous because users may rely on the skill for real-world elder safety, while the implementation may silently fail to provide the claimed protections or may process unrelated data flows under misleading pretenses.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-elderly-night-bed-exit-wandering-analysis"
description: "Using fixed cameras (infrared night vision) in nursing-home or home bedrooms, the system continuously monitors elderly bed-exit status and activity trajectory at night. | 通过养老院或居家卧室的固定摄像头(红外夜视),夜间连续监测老年人的离床状态和活动轨迹。输出异常预警,可联动护理人员手机或护士站大屏,防止老人走失、跌倒或发生意外。"
version: "1.0.15"
license: "MIT-0"
---

# 🛏️ Elderly Night Bed-Exit & Wandering Detection | 老年人夜间离床时长与徘徊识别
> **智能分析中枢** · �

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that uploaded attachments are automatically saved locally, but gives no user-facing warning or retention controls for highly sensitive bedroom surveillance data. Local persistence of intimate nighttime footage increases the risk of privacy violations, unauthorized access, and regulatory noncompliance if the storage location is insecure or retained longer than necessary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code silently derives or creates a user identity, performs remote login/registration, obtains tokens, and persists them locally for later reuse. That behavior is unrelated to the stated bedroom-monitoring analytics purpose and creates an undisclosed identity/bootstrap channel that could transmit user-linked data to external services and expand compromise impact if tokens or accounts are abused.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises execution of local scripts, file handling, network access, and possible environment-based identity handling, but does not declare any explicit tool scope or allowed-tools boundary. This creates unnecessary ambient authority and makes it harder for a host agent to constrain what the skill can access, increasing the blast radius if the script or prompt behavior is abused.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The default trigger activates on broadly described night monitoring videos without tight scoping, which can cause the skill to run on sensitive surveillance content unintentionally. In a bedroom-monitoring context, accidental activation raises privacy and compliance risk because highly sensitive footage may be processed or transmitted without sufficiently deliberate user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The keyword trigger list is broad and can match many loosely related caregiver or monitoring phrases, causing over-triggering on sensitive medical or surveillance workflows. Because this skill handles bedroom and hallway footage of elderly individuals, ambiguous invocation materially increases the chance of unauthorized or unintended processing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script includes functionality to resolve an internal user identity and retrieve prior analysis records by open_id, even though the stated skill purpose is bedside video analysis. Because open_id is hidden from normal help output and the list mode exposes historical records, the skill expands into user-context and record-access behavior without clear disclosure or demonstrated authorization checks in this file.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The call to resolve_current_open_id introduces a hidden user-context mechanism unrelated to the core task of analyzing a local or remote video. Hidden identity resolution increases the risk of unauthorized account linkage, cross-user data access, or silent use of ambient credentials, especially in a healthcare-monitoring context involving sensitive behavioral data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code initializes internal identity context without clear disclosure to the operator, using a suppressed parameter and automatic resolution path. In a system processing elderly bedroom monitoring data, undisclosed identity handling is particularly sensitive because it can enable access to private analysis records or tie surveillance outputs to individuals without transparent consent.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple user-visible strings are hard-coded in Chinese, such as the report heading and export-link text, which imposes a specific language on all users. The file does not provide locale selection, opt-in, or any documented reason that the skill is intended only for a Chinese-language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file returns several Chinese-only messages for empty results and validation failures, such as missing input, unsupported format, and file size errors. Because users are not offered a language/locale choice, this creates a natural-language policy issue under the locale requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code transmits either full local video contents or a user-supplied remote video URL to an external analysis API, but this file provides no user-facing notice, confirmation, or consent flow before sending highly sensitive bedroom monitoring data. In the stated context—elderly night-time surveillance in homes or nursing facilities—those videos may contain intimate health, behavioral, and location information, so silent transmission materially increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2