Back to skill

Security audit

Elderly Toilet Time Abnormal Detection (>30 min) | 老年人如厕时间异常(超30分钟)识别

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real bathroom-occupancy analysis tool, but it handles highly sensitive video, cloud history, identity, and token persistence with weak user control and privacy scoping.

Review before installing. Use this only if the monitored person or authorized caregiver has explicitly consented, you are comfortable sending bathroom-monitoring media and report history to the configured Lifeemergence cloud services, and you accept local identity/token storage in the workspace data directory. Prefer doorway-only or pre-blurred inputs, avoid uploading raw private bathroom footage, and confirm retention/access controls with the publisher.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (57)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, local file access including key material, identity creation/persistence, and workspace management are all materially broader than the advertised bathroom-occupancy monitor. Because the monitored content is intimate and medical-adjacent, undisclosed data flows and identity linkage significantly increase privacy, compliance, and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, local file access including key material, identity creation/persistence, and workspace management are all materially broader than the advertised bathroom-occupancy monitor. Because the monitored content is intimate and medical-adjacent, undisclosed data flows and identity linkage significantly increase privacy, compliance, and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, local file access including key material, identity creation/persistence, and workspace management are all materially broader than the advertised bathroom-occupancy monitor. Because the monitored content is intimate and medical-adjacent, undisclosed data flows and identity linkage significantly increase privacy, compliance, and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, local file access including key material, identity creation/persistence, and workspace management are all materially broader than the advertised bathroom-occupancy monitor. Because the monitored content is intimate and medical-adjacent, undisclosed data flows and identity linkage significantly increase privacy, compliance, and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, local file access including key material, identity creation/persistence, and workspace management are all materially broader than the advertised bathroom-occupancy monitor. Because the monitored content is intimate and medical-adjacent, undisclosed data flows and identity linkage significantly increase privacy, compliance, and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, local file access including key material, identity creation/persistence, and workspace management are all materially broader than the advertised bathroom-occupancy monitor. Because the monitored content is intimate and medical-adjacent, undisclosed data flows and identity linkage significantly increase privacy, compliance, and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, local file access including key material, identity creation/persistence, and workspace management are all materially broader than the advertised bathroom-occupancy monitor. Because the monitored content is intimate and medical-adjacent, undisclosed data flows and identity linkage significantly increase privacy, compliance, and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, local file access including key material, identity creation/persistence, and workspace management are all materially broader than the advertised bathroom-occupancy monitor. Because the monitored content is intimate and medical-adjacent, undisclosed data flows and identity linkage significantly increase privacy, compliance, and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, local file access including key material, identity creation/persistence, and workspace management are all materially broader than the advertised bathroom-occupancy monitor. Because the monitored content is intimate and medical-adjacent, undisclosed data flows and identity linkage significantly increase privacy, compliance, and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, local file access including key material, identity creation/persistence, and workspace management are all materially broader than the advertised bathroom-occupancy monitor. Because the monitored content is intimate and medical-adjacent, undisclosed data flows and identity linkage significantly increase privacy, compliance, and abuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound API requests, local file access including key material, identity creation/persistence, and workspace management are all materially broader than the advertised bathroom-occupancy monitor. Because the monitored content is intimate and medical-adjacent, undisclosed data flows and identity linkage significantly increase privacy, compliance, and abuse risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code can generate default identities, create local user records, and persist authentication-related state automatically when no explicit open-id is provided. For a toilet-occupancy alerting skill, silently establishing identities and storing auth context is unnecessary and dangerous because it can create undeclared accounts, tie activity to users without consent, and facilitate later authenticated network actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The shared utility contains broad account bootstrap, token handling, and arbitrary outbound HTTP functionality that is unrelated to elderly bathroom-occupancy monitoring. In this skill context, such generic networked identity operations greatly expand the attack surface and enable undisclosed data exfiltration, remote account actions, and backend coupling far beyond the stated purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool scope even though the documented workflow requires shell execution, network access, and local file handling. In a sensitive bathroom-monitoring context, this overbroad and undeclared capability set increases the risk of unintended file access, command execution, or data exfiltration because operators cannot constrain what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest frames the skill as privacy-limited silhouette-only monitoring, but the documentation expands inputs to generic images, videos, local files, URLs, and cloud history queries. That inconsistency is dangerous because it can induce users to submit more sensitive content than intended and obscures where that data may go.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

One section says the system should only output entry/exit statistics and alerts, while other sections instruct cloud history queries and report-link output. This mismatch weakens informed consent and data-minimization expectations by hiding broader reporting and retrieval functionality from users.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Overly broad trigger phrases for automatic history-report queries can cause the skill to invoke cloud retrieval unexpectedly, potentially exposing sensitive historical bathroom-monitoring records when the user did not clearly request them. In a high-privacy context, unintended retrieval itself is a meaningful security and confidentiality issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Automatically saving uploaded bathroom-monitoring media to local storage without a clear user-facing warning or retention policy creates unnecessary privacy risk. Because the content may include intimate or health-sensitive footage, silent local persistence increases the chance of unauthorized access, backup propagation, or retention beyond consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script exposes a hidden record-listing capability via --list and show_analyze_list(open_id, ...) that is outside the narrowly described purpose of analyzing a supplied bathroom video for prolonged occupancy. Hidden functionality that retrieves prior analyses increases the attack surface and can enable unauthorized access to historical monitoring data, especially because it is tied to an internal identity mechanism rather than explicit user authorization.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code initializes and relies on an internal open_id through OpenIdUtil.resolve_current_open_id(...) and then uses ConstantEnum.CURRENT__OPEN_ID to fetch analysis history, despite the manifest describing only video-based occupancy detection. In a bathroom-monitoring context, identity-linked record access is particularly sensitive because it may expose private health, behavior, and presence data if identity resolution is implicit or insufficiently authorized.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Multiple user-facing strings are hardcoded in Chinese, such as the report header and export-link text, and there is no indication that the user can choose another language. This creates a locale/language policy concern because the skill appears to enforce a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill accepts arbitrary HTTP/HTTPS video URLs and forwards them to the backend analysis service, which expands the behavior beyond the stated local camera monitoring use case. This can enable analysis of third-party or unintended remote content and may trigger backend access to attacker-controlled URLs, increasing privacy and service-abuse risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code reads arbitrary local file contents into memory and submits them to the analysis service without any user-facing notice or explicit consent in this flow. For a bathroom-monitoring elderly-care skill, this is sensitive because video files may contain highly private health and household data, so silent transmission materially increases privacy risk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2