Back to skill

Security audit

Smart E-Bike Detection Skill | 电动车智能检测技能

Security checks for vulnerabilities and agentic risk

Overview

The skill performs the advertised electric-vehicle media analysis, but it also silently creates or reuses user identities, registers/logs into a remote service, and stores tokens locally without enough user-facing disclosure.

Install only if you are comfortable sending surveillance images or videos to the configured lifeemergence.com cloud APIs and with the skill creating a persistent local identity/account record. Treat the workspace data directory and SQLite database as sensitive because they may contain service tokens. Review the provider, retention expectations, and legal/privacy obligations for any monitored area before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (57)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undisclosed identity generation/persistence, workspace discovery, local data access, and authenticated external API dispatch create a much broader data-handling surface than the skill description suggests. Because the content concerns uploaded surveillance media, hidden identity association and storage materially raise privacy and governance risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undisclosed identity generation/persistence, workspace discovery, local data access, and authenticated external API dispatch create a much broader data-handling surface than the skill description suggests. Because the content concerns uploaded surveillance media, hidden identity association and storage materially raise privacy and governance risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undisclosed identity generation/persistence, workspace discovery, local data access, and authenticated external API dispatch create a much broader data-handling surface than the skill description suggests. Because the content concerns uploaded surveillance media, hidden identity association and storage materially raise privacy and governance risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undisclosed identity generation/persistence, workspace discovery, local data access, and authenticated external API dispatch create a much broader data-handling surface than the skill description suggests. Because the content concerns uploaded surveillance media, hidden identity association and storage materially raise privacy and governance risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undisclosed identity generation/persistence, workspace discovery, local data access, and authenticated external API dispatch create a much broader data-handling surface than the skill description suggests. Because the content concerns uploaded surveillance media, hidden identity association and storage materially raise privacy and governance risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undisclosed identity generation/persistence, workspace discovery, local data access, and authenticated external API dispatch create a much broader data-handling surface than the skill description suggests. Because the content concerns uploaded surveillance media, hidden identity association and storage materially raise privacy and governance risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undisclosed identity generation/persistence, workspace discovery, local data access, and authenticated external API dispatch create a much broader data-handling surface than the skill description suggests. Because the content concerns uploaded surveillance media, hidden identity association and storage materially raise privacy and governance risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undisclosed identity generation/persistence, workspace discovery, local data access, and authenticated external API dispatch create a much broader data-handling surface than the skill description suggests. Because the content concerns uploaded surveillance media, hidden identity association and storage materially raise privacy and governance risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undisclosed identity generation/persistence, workspace discovery, local data access, and authenticated external API dispatch create a much broader data-handling surface than the skill description suggests. Because the content concerns uploaded surveillance media, hidden identity association and storage materially raise privacy and governance risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undisclosed identity generation/persistence, workspace discovery, local data access, and authenticated external API dispatch create a much broader data-handling surface than the skill description suggests. Because the content concerns uploaded surveillance media, hidden identity association and storage materially raise privacy and governance risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undisclosed identity generation/persistence, workspace discovery, local data access, and authenticated external API dispatch create a much broader data-handling surface than the skill description suggests. Because the content concerns uploaded surveillance media, hidden identity association and storage materially raise privacy and governance risk.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "electric-vehicle-detection-analysis"
description: "Automatically detects electric motorcycles and e-bikes in restricted areas based on computer vision. It supports real-time detection for both video streams and images, counts the number of illegal parking or driving instances, and triggers violation alerts to assist with safety management in parks, communities, and organizations. | 电动车智能检测技能,基于计算机视觉自动检测禁行区域内的电动摩托车/电动车,支持视频流和图片实时检测,统计违规停放/行驶数量,触发违规预警,助力园区/社区/单位安全管理"
version:

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file defines generic user/account persistence, including a sys_user table and user lookup/update routines, which is outside the declared electric-vehicle detection purpose. In a vision-detection skill, undisclosed account-management capability increases the risk of unnecessary collection, persistence, and mutation of user identity data, expanding the attack surface and enabling covert stateful tracking unrelated to the advertised function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The user model includes token and open_token fields, and the generic DAO update flows will persist and modify them despite the skill being described as EV detection. Storing authentication tokens in a local SQLite database without a clear need or security controls can expose credentials through filesystem access, backups, logs, or other local compromise, enabling account takeover or lateral movement.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility file contains broad identity, token, and remote API login/account-provisioning logic that is unrelated to the declared electric-vehicle detection purpose. Such hidden cross-domain capability expands the skill's privileges and enables network-backed account actions and credential handling that users would not reasonably expect from a computer-vision detection skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code can generate default user identities and create or persist them automatically when no explicit open-id is supplied. For an EV detection skill, silently creating identities is unjustified and dangerous because it can enroll users or devices into external systems without informed consent or clear operational need.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The helper performs a silent remote login/registration POST to a health-related API endpoint using generated or derived identifiers. This is unrelated to the stated CV/violation-analysis purpose and creates an undisclosed data transmission and account lifecycle action, making the skill materially more suspicious in context.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares no explicit tool restrictions even though the documented workflow requires shell execution, network access, local file reads/writes, and environment use. In an agent ecosystem, missing scope metadata weakens sandboxing and user visibility, increasing the chance that the skill is granted broader capabilities than necessary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description does not clearly warn users that uploaded local files and provided media URLs are sent to a cloud/API service for processing. This is dangerous because users may submit sensitive surveillance footage without informed consent about remote transfer, third-party processing, or jurisdictional/privacy implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow says uploaded attachments are automatically saved as local files but does not provide an explicit warning about local retention. For surveillance imagery and video, silent local storage increases the risk of unintended persistence, later disclosure, and noncompliant handling of sensitive footage.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill exposes a history-listing capability via show_analyze_list(open_id) that is outside the manifest’s stated scope of real-time/image detection and alerting. Undeclared data-retrieval features increase the risk of privacy leakage or unauthorized access to prior analysis records, especially if open_id can reference other users or if platform policy relies on the manifest to describe data access behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code initializes a hidden internal identity mechanism using OpenIdUtil.resolve_current_open_id(args.open_id, use_current=bool(args.open_id)) despite the skill being described as a computer-vision detection tool. Hidden identity plumbing expands the skill’s access scope beyond file/URL analysis and can enable correlation with user-specific records or backend actions that are not transparent to the operator.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The output header string is fixed to Chinese ("安管卫士电动车检测分析结构化结果") with no indication that users can select another language or that the skill is intentionally region-specific. This matches the policy category for language or locale constraints imposed without user opt-in.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2