Back to skill

Security audit

Fire & Smoke Detection Skill | 火情烟雾检测技能

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform fire/smoke analysis through a cloud service, but it silently creates and reuses local/cloud identities in ways that could mix report history between users.

Review before installing, especially in shared or multi-user OpenClaw workspaces. This skill sends media or URLs to lifeemergence.com cloud APIs, stores local identity/token data, and may reuse a shared fallback identity for history queries. Use only where cloud processing and local credential persistence are acceptable, and avoid shared workspaces until identity isolation is fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/fire_detection_analysis.py:53
Finding

Shared Fallback Identity Breaks Cross-User Report Isolation

Content
View full analysis

Vulnerability Details

File Location: scripts/fire_detection_analysis.py:53, skills/smyx_common/scripts/util.py:449-460
Vulnerability Type: Authentication context confusion and cross-user data access
Risk Level: High

Relevant code:

python
# scripts/fire_detection_analysis.py:53
OpenIdUtil.resolve_current_open_id(
    args.open_id,
    use_current=bool(args.open_id)
)
python
# skills/smyx_common/scripts/util.py:449-460
@classmethod
def resolve_current_open_id(cls, open_id=None, use_current=True):
    """Resolve and initialize the current open-id."""
    resolved_open_id = (open_id or "").strip() if isinstance(open_id, str) else open_id
    if not resolved_open_id and use_current:
        resolved_open_id = ConstantEnum.CURRENT__OPEN_ID or ConstantEnum.CURRENT__USER_NAME
    if not resolved_open_id:
        resolved_open_id = cls.get_api_key_file_open_id()
    if not resolved_open_id:
        resolved_open_id = cls.get_or_create_default_open_id()

    ConstantEnum.CURRENT__OPEN_ID = resolved_open_id
    if not ConstantEnum.CURRENT__USER_NAME:
        ConstantEnum.CURRENT__USER_NAME = resolved_open_id
    return resolved_open_id

Technical Analysis

The entry point sets use_current according to whether the hidden --open-id argument was explicitly supplied. During an ordinary invocation, args.open_id is absent and use_current becomes False.

Consequently, resolve_current_open_id() skips the current upstream identity stored in ConstantEnum.CURRENT__OPEN_ID or ConstantEnum.CURRENT__USER_NAME. Those values can be initialized from upstream sender environment variables, but they are ignored on the normal execution path.

The code instead selects an identity from the workspace-wide data/smyx-api-key.txt file or creates/reuses a default user from the shared SQLite database. API authentication and report filtering subsequently operate under this share ...[truncated 1929 chars]

Remediation
View remediation

Remediation Suggestions

  1. Always prefer the validated upstream sender identity when one is available:
    python
    OpenIdUtil.resolve_current_open_id(args.open_id, use_current=True)
    
  2. Remove the coupling between use_current and the presence of the hidden command-line argument.
  3. Use a generated fallback identity only when no authenticated upstream identity exists.
  4. Namespace fallback identities and local credential records by authenticated tenant and user rather than sharing one workspace-wide default.
  5. Enforce report ownership and tenant isolation on the server for list, result, and export endpoints; do not rely solely on a client-supplied username.
  6. Add integration tests with two distinct upstream users to verify that each user can list and retrieve only their own analysis records.
  7. Reject ambiguous identity states instead of silently falling back in multi-user deployments.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (55)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of external API requests, auth handling, local file writes, environment/workspace detection, and automatic user identity creation is materially broader than the advertised early-warning detector. In a surveillance context, those hidden behaviors increase the risk of secret leakage, persistent local artifacts, unintended account linkage, and off-device data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The combination of external API requests, auth handling, local file writes, environment/workspace detection, and automatic user identity creation is materially broader than the advertised early-warning detector. In a surveillance context, those hidden behaviors increase the risk of secret leakage, persistent local artifacts, unintended account linkage, and off-device data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The combination of external API requests, auth handling, local file writes, environment/workspace detection, and automatic user identity creation is materially broader than the advertised early-warning detector. In a surveillance context, those hidden behaviors increase the risk of secret leakage, persistent local artifacts, unintended account linkage, and off-device data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The combination of external API requests, auth handling, local file writes, environment/workspace detection, and automatic user identity creation is materially broader than the advertised early-warning detector. In a surveillance context, those hidden behaviors increase the risk of secret leakage, persistent local artifacts, unintended account linkage, and off-device data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The combination of external API requests, auth handling, local file writes, environment/workspace detection, and automatic user identity creation is materially broader than the advertised early-warning detector. In a surveillance context, those hidden behaviors increase the risk of secret leakage, persistent local artifacts, unintended account linkage, and off-device data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of external API requests, auth handling, local file writes, environment/workspace detection, and automatic user identity creation is materially broader than the advertised early-warning detector. In a surveillance context, those hidden behaviors increase the risk of secret leakage, persistent local artifacts, unintended account linkage, and off-device data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of external API requests, auth handling, local file writes, environment/workspace detection, and automatic user identity creation is materially broader than the advertised early-warning detector. In a surveillance context, those hidden behaviors increase the risk of secret leakage, persistent local artifacts, unintended account linkage, and off-device data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The combination of external API requests, auth handling, local file writes, environment/workspace detection, and automatic user identity creation is materially broader than the advertised early-warning detector. In a surveillance context, those hidden behaviors increase the risk of secret leakage, persistent local artifacts, unintended account linkage, and off-device data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of external API requests, auth handling, local file writes, environment/workspace detection, and automatic user identity creation is materially broader than the advertised early-warning detector. In a surveillance context, those hidden behaviors increase the risk of secret leakage, persistent local artifacts, unintended account linkage, and off-device data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of external API requests, auth handling, local file writes, environment/workspace detection, and automatic user identity creation is materially broader than the advertised early-warning detector. In a surveillance context, those hidden behaviors increase the risk of secret leakage, persistent local artifacts, unintended account linkage, and off-device data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of external API requests, auth handling, local file writes, environment/workspace detection, and automatic user identity creation is materially broader than the advertised early-warning detector. In a surveillance context, those hidden behaviors increase the risk of secret leakage, persistent local artifacts, unintended account linkage, and off-device data exposure.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "fire-detection-analysis"
description: "Real-time detection of flames and smoke in video and image scenes. Suitable for fire early warning in industrial parks, forests, warehouses, and other locations. | 火情烟雾检测技能,实时检测视频/图片场景中的火焰、烟雾,适用于工业园区、森林、仓库等场所火情预警"
license: "MIT-0"
---

This capability supports real-time detection of flames and smoke in video streams or images, making it suitable for high
fire-risk locations such as industrial parks, forests, and warehouses. Based on color features, dynamic texture
analysis, and smoke dif

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The DAO exposes full create, update, and delete operations for persistent user records unrelated to fire analysis. In the context of a vision skill, these extra data-management capabilities are suspicious and dangerous because they allow silent modification or destruction of user/account data without any apparent least-privilege boundary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file defines persistent user/account data handling inside a fire/smoke detection skill, which is unrelated to the stated purpose. Capability mismatch is dangerous because it increases the attack surface and may enable covert identity or token handling under the cover of an innocuous computer-vision skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The User model stores profile attributes and sensitive authentication material such as token and open_token, which are not justified by a fire-detection feature. Unnecessary credential storage materially raises the risk of account compromise, privacy violations, and lateral movement if the local database is accessed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code reads an internal identity from a local file, reuses existing local identities, or creates new default users when none are supplied. Implicit identity creation and persistence are not justified by fire/smoke detection functionality and create a hidden authentication surface that can be abused for impersonation, activity attribution confusion, and silent account linkage.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility file includes account discovery, identity creation, token acquisition, token persistence, and authenticated remote API request logic that is unrelated to the declared fire/smoke detection purpose. In the context of a computer-vision safety skill, this materially expands capabilities into identity and network operations, increasing the chance of covert data transmission, unauthorized account actions, and supply-chain style misuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The HTTP helper silently contacts an external health endpoint to perform phone-login style registration, then stores returned tokens for future use. That behavior is unrelated to image/video fire detection and is especially dangerous because it enables undisclosed remote account provisioning and credential handling behind a generic request helper.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares powerful capabilities in its instructions and referenced scripts (shell execution, file access, network/API access, environment usage) but does not scope or constrain them with explicit permissions metadata. This increases the risk of over-privileged execution and makes it harder for a host system or reviewer to enforce least privilege, especially because the skill also instructs automatic local file saving and cloud API calls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrases for historical report retrieval are broad enough to match ordinary user requests and automatically invoke cloud queries. This can cause unintentional disclosure of historical report metadata or links, especially because the skill also states that identity association happens automatically without user-visible confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill says uploaded attachments are automatically saved as local files, but the user-facing description does not clearly warn about this storage behavior. For potentially sensitive surveillance images and videos, undisclosed local persistence creates privacy, retention, and forensic exposure risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill lacks a clear privacy disclosure that network URLs and historical report queries are sent to a cloud API. Because the content involves security-camera or incident media, undisclosed remote transfer materially increases privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents behaviors that may affect user data and privacy, including API key-based authentication, file uploads, historical report queries, and full report export, but it provides no warning or disclosure about handling sensitive data. Under the markdown-specific warning criterion, users should be informed about potential data exposure, credential handling, or privacy impact of these operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The argument parser description and help strings are entirely in Chinese, and the runtime status/error messages are also Chinese-only. This imposes a specific language on all users without offering opt-in, fallback, or documenting that the tool is intended only for a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L17 hardcodes the user-facing analysis header in Chinese ("火情烟雾检测分析结构化结果"). This imposes a specific language on users without any opt-in, selection mechanism, or justification, which matches the natural-language locale policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2