Back to skill

Security audit

Fish Feeding Behavior Activity Analysis | 鱼类摄食行为活跃度分析

Security checks for vulnerabilities and agentic risk

Overview

This skill is review-worthy because it sends fish-feeding media to a cloud service and quietly creates and reuses account-linked identities and tokens across sessions.

Install only if you are comfortable with aquarium videos or supplied URLs being processed by the Life Emergence cloud service and with the skill creating/reusing a persistent internal identity plus cached tokens for report history. Reviewers should require clearer consent, retention, token handling, and history-query controls before treating it as low-risk.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (52)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported implementation includes external HTTP communication, token acquisition/retry logic, workspace inspection, local file access, and user/open-id generation and persistence, which are much broader than the advertised analytics feature. This combination is dangerous because it can silently connect user media, local state, and identity to remote services under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported implementation includes external HTTP communication, token acquisition/retry logic, workspace inspection, local file access, and user/open-id generation and persistence, which are much broader than the advertised analytics feature. This combination is dangerous because it can silently connect user media, local state, and identity to remote services under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported implementation includes external HTTP communication, token acquisition/retry logic, workspace inspection, local file access, and user/open-id generation and persistence, which are much broader than the advertised analytics feature. This combination is dangerous because it can silently connect user media, local state, and identity to remote services under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported implementation includes external HTTP communication, token acquisition/retry logic, workspace inspection, local file access, and user/open-id generation and persistence, which are much broader than the advertised analytics feature. This combination is dangerous because it can silently connect user media, local state, and identity to remote services under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported implementation includes external HTTP communication, token acquisition/retry logic, workspace inspection, local file access, and user/open-id generation and persistence, which are much broader than the advertised analytics feature. This combination is dangerous because it can silently connect user media, local state, and identity to remote services under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported implementation includes external HTTP communication, token acquisition/retry logic, workspace inspection, local file access, and user/open-id generation and persistence, which are much broader than the advertised analytics feature. This combination is dangerous because it can silently connect user media, local state, and identity to remote services under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported implementation includes external HTTP communication, token acquisition/retry logic, workspace inspection, local file access, and user/open-id generation and persistence, which are much broader than the advertised analytics feature. This combination is dangerous because it can silently connect user media, local state, and identity to remote services under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported implementation includes external HTTP communication, token acquisition/retry logic, workspace inspection, local file access, and user/open-id generation and persistence, which are much broader than the advertised analytics feature. This combination is dangerous because it can silently connect user media, local state, and identity to remote services under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported implementation includes external HTTP communication, token acquisition/retry logic, workspace inspection, local file access, and user/open-id generation and persistence, which are much broader than the advertised analytics feature. This combination is dangerous because it can silently connect user media, local state, and identity to remote services under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported implementation includes external HTTP communication, token acquisition/retry logic, workspace inspection, local file access, and user/open-id generation and persistence, which are much broader than the advertised analytics feature. This combination is dangerous because it can silently connect user media, local state, and identity to remote services under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported implementation includes external HTTP communication, token acquisition/retry logic, workspace inspection, local file access, and user/open-id generation and persistence, which are much broader than the advertised analytics feature. This combination is dangerous because it can silently connect user media, local state, and identity to remote services under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported implementation includes external HTTP communication, token acquisition/retry logic, workspace inspection, local file access, and user/open-id generation and persistence, which are much broader than the advertised analytics feature. This combination is dangerous because it can silently connect user media, local state, and identity to remote services under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-fish-feeding-activity-analysis"
description: "Through built-in cameras of smart feeders or fixed cameras on aquariums, the system captures fish feeding videos after feeding. Using AI object detection and motion analysis, it identifies the number of fish gathering for food, feeding intensity (fish swimming speed, feeding action frequency), and remaining feed amount, and computes a comprehensive feeding activity score (0-100). | 通过智能喂食器内置摄像头或鱼缸固定摄像头,在投喂后拍摄鱼群摄食视频,利用 AI 目标检测和运动分析技术,识别鱼群聚集抢食的数量、摄食强度(�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The utility layer performs remote account provisioning, token acquisition, token caching, and authenticated API request handling that are unrelated to fish feeding video analysis. This creates hidden identity bootstrapping and external service access, increasing the risk of undisclosed data exfiltration, unauthorized account creation, and cross-skill token misuse in a context where users would not reasonably expect such behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares no explicit tool scope or permission boundaries even though its documented behavior requires shell execution, network access, environment access, and local file handling. This increases the attack surface because an agent may grant broader capabilities than users expect, making misuse of file, shell, or network operations easier if the skill or backing scripts are compromised or behave unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The history-report trigger phrases are broad enough that ordinary user requests may automatically invoke cloud history lookup. In a skill that ties reports to internally managed identity, this can cause unintended disclosure or retrieval of account-linked historical data without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that uploaded attachments are automatically saved locally, but the static finding notes this is not surfaced as a clear upfront user-facing warning. Silent local persistence creates privacy and retention risk, especially for media files that may contain sensitive environmental or location details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

User-provided network URLs are sent to an external API service for fetching, but the finding indicates this is not clearly disclosed upfront. That creates both privacy and SSRF-style trust-boundary concerns because users may not realize a third-party service will contact the supplied URL and process the content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script exposes a history-listing feature tied to a user identity even though the advertised skill scope is only single-video feeding analysis. Hidden or undocumented data-access functionality increases the chance of unauthorized access to prior analysis records, especially if callers can influence identity resolution or invoke --list unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script initializes an internal open_id and uses it for listing behavior despite that identity being unrelated to local video analysis. Introducing hidden identity handling into a media-analysis tool expands the trust boundary and can enable privacy leakage, cross-user data access, or unexpected linkage of analysis actions to internal accounts.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill reads arbitrary local files and uploads them, or submits arbitrary remote video URLs to a backend analysis service, without any visible notice, consent flow, destination disclosure, or minimization controls in this code. In a camera/video-analysis context, that can expose sensitive aquarium, household, or environment footage and metadata to external processing unexpectedly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes analyzing feeding videos to compute activity metrics and appetite warnings, but this code also provides a separate capability to enumerate prior analysis reports and generate export image URLs for them. That is a broader report-management/retrieval behavior not described in the manifest's stated scope of performing analysis on supplied video data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code accepts an --api-key argument, which is a sensitive credential, but the parameter is hidden from help output and there is no visible comment, prompt, or user-facing disclosure explaining that credentials may be supplied and used. For code files, access to sensitive credentials without any user disclosure qualifies as a missing warning unless the behavior is clearly disclosed elsewhere in the file.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2