Back to skill

Security audit

Fish Egg Incubation Stage Identification | 鱼卵孵化状态识别

Security checks for vulnerabilities and agentic risk

Overview

The skill does perform the advertised fish-egg media analysis through a cloud API, but it also silently creates or reuses identities, stores authentication tokens locally, and has a runtime import-path weakness that deserves manual review before installation.

Install only if you are comfortable with media and history requests going to lifeemergence.com services and with the skill creating/reusing a local identity database that may store session tokens. Prefer running it in an isolated workspace, avoid shared temporary install paths, and review/delete the workspace data files if you do not want persistent identity linkage.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/smyx_fish_egg_incubation_stage_analysis.py:5
Finding

Arbitrary Code Execution Through Python Import Path Hijacking

Content
View full analysis

Vulnerability Details

File Location: scripts/smyx_fish_egg_incubation_stage_analysis.py, lines 5–7 and 16–18
Vulnerability Type: Python import path hijacking through an attacker-writable temporary directory
Risk Level: High

Vulnerable Code

python
current_dir = os.path.dirname(os.path.abspath(__file__))
parent_dir = os.path.dirname(os.path.dirname(os.path.dirname(current_dir)))
sys.path.insert(0, parent_dir)

# ...

from .config import *

from .skill import skill

from skills.smyx_common.scripts.util import RequestUtil, OpenIdUtil

Technical Analysis

The entry point derives an import root by traversing three parent directories from the directory containing the script, then inserts the resulting path at the beginning of sys.path.

For the audited project location:

text
/tmp/clawhub-codex-scan-v575mhsfx8ypzk0nn07417wa3n8fbvtm-Gs8XLi/artifact/scripts

the three parent traversals resolve as follows:

text
1. /tmp/clawhub-codex-scan-v575mhsfx8ypzk0nn07417wa3n8fbvtm-Gs8XLi/artifact
2. /tmp/clawhub-codex-scan-v575mhsfx8ypzk0nn07417wa3n8fbvtm-Gs8XLi
3. /tmp

Consequently, /tmp is inserted at index zero of Python's module search path. The entry point subsequently performs absolute imports under the skills namespace. Because /tmp is generally writable by other local users, an attacker can place a counterfeit skills package there. Python can then load attacker-controlled package initialization code or modules before reaching the legitimate project modules.

This is a concrete cross-user trust-boundary violation when the Skill runs from the audited temporary-directory layout. The attacker does not need to modify the Skill package itself; write access to the shared temporary directory is sufficient.

Attack Path

  1. A local attacker with write access to /tmp creates a counterfeit package hierarchy, for example:

    text
    /tmp/skills/__init__.py
    /tmp/skills/smyx_common/__init__.py
    /tmp/skills/smyx_co
    

...[truncated 1463 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the dynamic sys.path.insert(0, parent_dir) modification and install or invoke the project as a properly packaged Python module.

  2. Use package-relative imports where the modules belong to the same trusted distribution.

  3. If import-path bootstrapping is unavoidable:

    • Resolve the exact project root rather than traversing a fixed number of parent directories.
    • Verify that the resolved root is inside the expected project directory.
    • Reject shared temporary directories and locations writable by untrusted users.
    • Validate directory ownership and permissions before adding it to sys.path.
    • Avoid placing the path at index zero unless precedence over installed packages is strictly necessary.
  4. Run the Skill from a private directory owned by the invoking account, with permissions preventing modification by other users.

  5. Add a startup assertion that imported shared modules originate from the expected project root, for example by validating each module's resolved __file__ path.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (60)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code reportedly reads local credential files, creates persistent identities, logs users into backend APIs, stores tokens, and performs external requests, none of which are necessary for the stated image-analysis assistant role. In this context, the mismatch is highly dangerous because it can expose local secrets, create covert account linkage, and exfiltrate user-linked data under a harmless-seeming cover story.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code reportedly reads local credential files, creates persistent identities, logs users into backend APIs, stores tokens, and performs external requests, none of which are necessary for the stated image-analysis assistant role. In this context, the mismatch is highly dangerous because it can expose local secrets, create covert account linkage, and exfiltrate user-linked data under a harmless-seeming cover story.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code reportedly reads local credential files, creates persistent identities, logs users into backend APIs, stores tokens, and performs external requests, none of which are necessary for the stated image-analysis assistant role. In this context, the mismatch is highly dangerous because it can expose local secrets, create covert account linkage, and exfiltrate user-linked data under a harmless-seeming cover story.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code reportedly reads local credential files, creates persistent identities, logs users into backend APIs, stores tokens, and performs external requests, none of which are necessary for the stated image-analysis assistant role. In this context, the mismatch is highly dangerous because it can expose local secrets, create covert account linkage, and exfiltrate user-linked data under a harmless-seeming cover story.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code reportedly reads local credential files, creates persistent identities, logs users into backend APIs, stores tokens, and performs external requests, none of which are necessary for the stated image-analysis assistant role. In this context, the mismatch is highly dangerous because it can expose local secrets, create covert account linkage, and exfiltrate user-linked data under a harmless-seeming cover story.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code reportedly reads local credential files, creates persistent identities, logs users into backend APIs, stores tokens, and performs external requests, none of which are necessary for the stated image-analysis assistant role. In this context, the mismatch is highly dangerous because it can expose local secrets, create covert account linkage, and exfiltrate user-linked data under a harmless-seeming cover story.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code reportedly reads local credential files, creates persistent identities, logs users into backend APIs, stores tokens, and performs external requests, none of which are necessary for the stated image-analysis assistant role. In this context, the mismatch is highly dangerous because it can expose local secrets, create covert account linkage, and exfiltrate user-linked data under a harmless-seeming cover story.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code reportedly reads local credential files, creates persistent identities, logs users into backend APIs, stores tokens, and performs external requests, none of which are necessary for the stated image-analysis assistant role. In this context, the mismatch is highly dangerous because it can expose local secrets, create covert account linkage, and exfiltrate user-linked data under a harmless-seeming cover story.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code reportedly reads local credential files, creates persistent identities, logs users into backend APIs, stores tokens, and performs external requests, none of which are necessary for the stated image-analysis assistant role. In this context, the mismatch is highly dangerous because it can expose local secrets, create covert account linkage, and exfiltrate user-linked data under a harmless-seeming cover story.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code reportedly reads local credential files, creates persistent identities, logs users into backend APIs, stores tokens, and performs external requests, none of which are necessary for the stated image-analysis assistant role. In this context, the mismatch is highly dangerous because it can expose local secrets, create covert account linkage, and exfiltrate user-linked data under a harmless-seeming cover story.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code reportedly reads local credential files, creates persistent identities, logs users into backend APIs, stores tokens, and performs external requests, none of which are necessary for the stated image-analysis assistant role. In this context, the mismatch is highly dangerous because it can expose local secrets, create covert account linkage, and exfiltrate user-linked data under a harmless-seeming cover story.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code reportedly reads local credential files, creates persistent identities, logs users into backend APIs, stores tokens, and performs external requests, none of which are necessary for the stated image-analysis assistant role. In this context, the mismatch is highly dangerous because it can expose local secrets, create covert account linkage, and exfiltrate user-linked data under a harmless-seeming cover story.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-fish-egg-incubation-stage-analysis"
description: "Through breeding-tank fixed cameras (macro lens), the system periodically captures high-definition images of fish eggs and uses AI vision analysis to detect egg color changes (transparent → white / black) and embryonic eye-spots (small black dots), identifying incubation stages (unfertilized / early / mid / late-eyespot / hatching). | 通过繁殖缸固定摄像头(微距镜头),定期拍摄鱼卵的高清图像,利用 AI 视觉分析技术检测鱼卵颜色变化(透明 → 发白/发黑)以及胚胎眼睛点(黑色小点)的出现,识别鱼卵的孵化阶段

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation accepts either arbitrary local files or any http/https URL as analysis input, which is broader than the declared fixed-camera fish-egg image analysis purpose. This scope mismatch can enable misuse of the skill as a generic media upload/analysis proxy, increasing risks around unauthorized data processing, privacy violations, and policy bypass.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation accepts arbitrary local video paths or remote video URLs and performs generic analysis, which materially exceeds the manifest’s narrowly described fixed-camera fish-egg incubation use case. This kind of capability mismatch is dangerous because it can enable unreviewed data ingestion and exfiltration to downstream analysis services, broadening the attack surface beyond the declared purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file exposes broad generic network and CRUD primitives (add, edit, delete, http_get, http_post, http_put, http_delete) that can be used for arbitrary external interactions unrelated to fish-egg image analysis. In the context of a narrowly scoped vision-analysis skill, this unnecessary capability expansion increases the attack surface and enables misuse for data exfiltration, remote command-and-control style communication, or unauthorized modification of remote resources if other parts of the skill can influence the URLs or payloads.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill is supposed to analyze fish-egg incubation images, but the file defines a generic user/account datastore with persistent identity fields and user lookup/update logic unrelated to that purpose. Such hidden or unjustified identity management expands the data-collection surface, enables unnecessary retention of personal data, and creates a covert persistence mechanism that could be abused by other parts of the skill ecosystem.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The User model stores token and open_token fields even though the skill's declared function is fish-egg incubation stage analysis. Persisting authentication-style secrets in a local SQLite database without clear need materially increases credential exposure risk through local file access, backups, logs, or later code reuse, and the mismatch with the skill's purpose makes the behavior more suspicious.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This utility module performs broad authenticated API activity, token handling, user lookup, and auto-provisioning that is unrelated to fish-egg incubation image analysis. The mismatch between declared skill purpose and implemented capabilities increases the risk of covert account use, unauthorized network activity, and silent data handling beyond user expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code can silently call a remote /sys/phoneLogin endpoint with register=1 and user identity fields, effectively creating or recovering platform accounts without clear user initiation. For a camera-based egg-stage analysis skill, this is unjustified functionality and could be abused to enroll identities, associate activity with unexpected accounts, or trigger unauthorized backend actions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill requests or implies broad capabilities including shell, filesystem, environment, and network access, but does not declare any explicit tool scope or permission boundaries. In an agent setting, this increases the chance of over-privileged execution and makes it harder to enforce least privilege or detect abuse of local files, credentials, or outbound requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default activation rule is broad enough that the skill may auto-trigger on many fish-egg-related uploads without clear exclusion criteria. In an over-privileged skill that saves files and calls cloud APIs, broad auto-triggering increases the risk of unintended file handling and data transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states that uploaded attachments are automatically saved locally but does not present that as a clear privacy warning to users. Silent local persistence of media can create retention, leakage, and multi-user privacy risks, especially when the input may contain sensitive or proprietary footage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The history-query behavior sends requests directly to a cloud API and may transmit identity-linked data, but the description lacks a clear privacy and integrity warning. Users may believe they are only doing local analysis when in fact records are being fetched from or correlated with a remote service.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Automatically creating or reusing a local default user identity is not justified for simple fish-egg media analysis and introduces silent identity persistence. This can cause cross-session tracking, accidental access to another user's records, and privacy issues if multiple users share a device or workspace.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2