Back to skill

Security audit

Farrowing/Hatching Monitoring

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a cloud video-analysis wrapper, but it silently creates or reuses an account and stores reusable access tokens locally in ways users should review before installing.

Install only if you are comfortable sending monitoring media to the Life Emergence cloud service and having this skill silently create or reuse an internal account. Review token storage and dependency handling first, and avoid using it in a workspace shared with untrusted skills until credential persistence and authenticated request destination checks are hardened.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/util.py:568
Finding

Authentication Credentials Can Be Forwarded to Arbitrary Network Destinations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/dao.py:460
Finding

Cloud Authentication Tokens Are Persisted in Plaintext in a Shared SQLite Database

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skills/smyx_analysis/requirements.txt:3
Finding

Ambiguous YAML Dependency Declaration Creates Dependency-Confusion and Installation Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (48)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-farrowing-hatching-monitoring-analysis"
description: "Monitors farrowing and poultry hatching events from continuous videos of farrowing pens or hatching areas — detecting key milestones such as water breaking, straining, piglet delivery, egg pipping and chick emergence — and outputs real-time event reminders. | 识别母猪产仔、禽类孵化等关键繁殖事件,实时提醒。"
version: "1.0.1"
license: "MIT-0"
---

# 🐣 Farrowing & Hatching Monitoring | 产仔/孵化监控

> 识别母猪产仔、禽类孵化等关键繁殖事件,实时提醒。
>
> **关键繁殖事件监控中枢** · 产房/孵化区连续视频�

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
83% confidence
Finding

The document mandates a specific output format in Markdown and the surrounding skill content consistently constrains output labels and examples to Chinese, without stating that users may choose another language. For a general-purpose skill description, this can amount to a locale/language policy violation because it imposes a language without opt-in or explicit regional justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility layer performs token management, automatic account lookup/provisioning, and outbound API access that are unrelated to the stated farrowing/hatching video-monitoring purpose. A skill with hidden identity bootstrapping and remote tokenized communication can exfiltrate user/workspace identity, silently bind actions to backend accounts, and expand scope far beyond what a user expects from local event monitoring.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill declares powerful behaviors such as shell execution, file access, network access, and environment interaction, but does not define any explicit tool scope or allowed-tools boundary. In an agent environment, this increases the chance of over-broad tool use, accidental data exposure, or command execution beyond the user’s expected task.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auto-trigger phrases for historical report lookup are broad enough to match ordinary conversational requests, which can cause unintended backend queries and disclosure of past report metadata. In a skill that links results to an internal identity, accidental triggering raises privacy and authorization concerns.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill says uploaded media will be automatically saved locally, but does not prominently warn users about retention, storage location, or lifecycle. Silent local persistence of user-provided video can expose sensitive operational footage to other processes, users, or future tasks on the same system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill transmits user-provided media to a server-side API but does not provide a clear upfront disclosure of external transmission and remote processing. For continuous video from farms or facilities, this can expose sensitive operational data and violate user expectations or policy requirements.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says this skill monitors farrowing pens and hatching areas for sow and poultry reproductive events, but the exposed CLI interface asks users to choose pet types 'cat', 'dog', or 'other'. That indicates the implemented behavior/interface is repurposed from a general pet workflow rather than a purpose-built farrowing/hatching monitor, which materially mismatches the declared scope.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple returned messages are fixed in Chinese, such as the analysis report headings and status/error strings. This imposes a specific locale on all users with no opt-in, language selection, or documented region-specific justification, which matches the stated language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest describes a monitoring skill for continuous videos of farrowing or hatching areas, which implies analysis of provided monitoring footage. The code also supports directly ingesting any HTTP/HTTPS URL as a video source, broadening the behavior to remote network retrieval/submission not stated in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill reads arbitrary local file content into memory and submits it to the analysis service without any user-visible consent, disclosure, or narrowing of permissible paths in this code path. In an agent setting, this can lead to unintended exfiltration of sensitive local videos or files if a caller supplies a path the user did not realize would be uploaded.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2