T09 · Insecure Skill Coding Practices
- Location
skills/smyx_common/scripts/util.py:568- Finding
Authentication Credentials Can Be Forwarded to Arbitrary Network Destinations
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a cloud video-analysis wrapper, but it silently creates or reuses an account and stores reusable access tokens locally in ways users should review before installing.
Install only if you are comfortable sending monitoring media to the Life Emergence cloud service and having this skill silently create or reuse an internal account. Review token storage and dependency handling first, and avoid using it in a workspace shared with untrusted skills until credential persistence and authenticated request destination checks are hardened.
skills/smyx_common/scripts/util.py:568Authentication Credentials Can Be Forwarded to Arbitrary Network Destinations
skills/smyx_common/scripts/dao.py:460Cloud Authentication Tokens Are Persisted in Plaintext in a Shared SQLite Database
skills/smyx_analysis/requirements.txt:3Ambiguous YAML Dependency Declaration Creates Dependency-Confusion and Installation Risk
The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.
The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.
The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.
The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.
The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.
The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.
The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.
The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.
The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.
The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.
The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.
The skill appears to combine external API communication, authentication/token handling, local filesystem writes, environment detection, and local user/database interaction while presenting itself as a specialized monitoring tool. This is dangerous because the true trust boundary is much larger than advertised, increasing risks of credential misuse, data leakage, and unauthorized persistence.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
---
name: "smyx-farrowing-hatching-monitoring-analysis"
description: "Monitors farrowing and poultry hatching events from continuous videos of farrowing pens or hatching areas — detecting key milestones such as water breaking, straining, piglet delivery, egg pipping and chick emergence — and outputs real-time event reminders. | 识别母猪产仔、禽类孵化等关键繁殖事件,实时提醒。"
version: "1.0.1"
license: "MIT-0"
---
# 🐣 Farrowing & Hatching Monitoring | 产仔/孵化监控
> 识别母猪产仔、禽类孵化等关键繁殖事件,实时提醒。
>
> **关键繁殖事件监控中枢** · 产房/孵化区连续视频�
The document mandates a specific output format in Markdown and the surrounding skill content consistently constrains output labels and examples to Chinese, without stating that users may choose another language. For a general-purpose skill description, this can amount to a locale/language policy violation because it imposes a language without opt-in or explicit regional justification.
This utility layer performs token management, automatic account lookup/provisioning, and outbound API access that are unrelated to the stated farrowing/hatching video-monitoring purpose. A skill with hidden identity bootstrapping and remote tokenized communication can exfiltrate user/workspace identity, silently bind actions to backend accounts, and expand scope far beyond what a user expects from local event monitoring.
The skill declares powerful behaviors such as shell execution, file access, network access, and environment interaction, but does not define any explicit tool scope or allowed-tools boundary. In an agent environment, this increases the chance of over-broad tool use, accidental data exposure, or command execution beyond the user’s expected task.
The auto-trigger phrases for historical report lookup are broad enough to match ordinary conversational requests, which can cause unintended backend queries and disclosure of past report metadata. In a skill that links results to an internal identity, accidental triggering raises privacy and authorization concerns.
The skill says uploaded media will be automatically saved locally, but does not prominently warn users about retention, storage location, or lifecycle. Silent local persistence of user-provided video can expose sensitive operational footage to other processes, users, or future tasks on the same system.
The skill transmits user-provided media to a server-side API but does not provide a clear upfront disclosure of external transmission and remote processing. For continuous video from farms or facilities, this can expose sensitive operational data and violate user expectations or policy requirements.
The manifest says this skill monitors farrowing pens and hatching areas for sow and poultry reproductive events, but the exposed CLI interface asks users to choose pet types 'cat', 'dog', or 'other'. That indicates the implemented behavior/interface is repurposed from a general pet workflow rather than a purpose-built farrowing/hatching monitor, which materially mismatches the declared scope.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)
result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
dict) else result_json
if result_json_common_ai_response:
result_json = result_json_common_ai_response
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)
result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
dict) else result_json
if result_json_common_ai_response:
result_json = result_json_common_ai_response
Multiple returned messages are fixed in Chinese, such as the analysis report headings and status/error strings. This imposes a specific locale on all users with no opt-in, language selection, or documented region-specific justification, which matches the stated language/locale policy violation criteria.
The manifest describes a monitoring skill for continuous videos of farrowing or hatching areas, which implies analysis of provided monitoring footage. The code also supports directly ingesting any HTTP/HTTPS URL as a video source, broadening the behavior to remote network retrieval/submission not stated in the manifest.
The skill reads arbitrary local file content into memory and submits it to the analysis service without any user-visible consent, disclosure, or narrowing of permissible paths in this code path. In an agent setting, this can lead to unintended exfiltration of sensitive local videos or files if a caller supplies a path the user did not realize would be uploaded.
Detected: suspicious.install_untrusted_source