Back to skill

Security audit

Fish Gasping & Ammonia Poisoning Visual Warning | 水族箱内氨氮中毒视觉预兆(鱼浮头)

Security checks for vulnerabilities and agentic risk

Overview

This skill appears aimed at aquarium video analysis, but it silently creates and stores user identity tokens and accesses cloud report history in ways users may not expect.

Install only if you are comfortable sending aquarium videos or video URLs to the LifeEmergence cloud service and having the skill create/reuse an internal identity for cloud reports. Review where the workspace data directory is stored, whether tokens are retained there, and whether report-history lookup should require explicit confirmation.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T07 · Tool Hijacking and Spoofing

Warning
Location
scripts/smyx_fish_gasping_ammonia_warning_analysis.py:2
Finding

World-Writable Directory Prepending Enables Python Module Hijacking

Content
View full analysis

Vulnerability Details

File Location: scripts/smyx_fish_gasping_ammonia_warning_analysis.py, lines 2–23
Vulnerability Type: Python module search-path hijacking
Risk Level: Medium

Vulnerable Code

python
import sys
import os

current_dir = os.path.dirname(os.path.abspath(__file__))
parent_dir = os.path.dirname(os.path.dirname(os.path.dirname(current_dir)))
sys.path.insert(0, parent_dir)

import argparse
import json
import mimetypes
import traceback
from datetime import datetime

import requests
import sys
import os

from .config import *

from .skill import skill

from skills.smyx_common.scripts.util import RequestUtil, OpenIdUtil

Technical Analysis

The entry point ascends three directory levels from its own directory and prepends the resulting path to Python's module search path.

In the audited deployment layout, the script is located at:

text
/tmp/clawhub-codex-scan-v571h9h0jptdvfxd0we9b49zv58f6eyy-pdbrLt/artifact/scripts/

Ascending three levels resolves parent_dir to /tmp. The call to:

python
sys.path.insert(0, parent_dir)

therefore places a generally world-writable directory ahead of trusted package locations. Subsequent imports, including requests and skills.smyx_common..., may resolve to attacker-created modules or packages in /tmp.

Python executes top-level module code during import. Consequently, a local attacker who can create files in /tmp can arrange for arbitrary Python code to execute when the documented Skill entry point is invoked. The malicious module does not need to modify the audited project itself.

Attack Path

  1. A lower-privileged local attacker determines that the Skill is installed under the audited temporary-directory structure.
  2. The attacker creates a malicious import candidate in /tmp, such as:
    • /tmp/requests.py; or
    • a spoofed /tmp/skills/ package with the expected module hi ...[truncated 1474 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the manual sys.path modification and invoke the entry point as part of an installed or properly configured Python package.

  2. Use a package entry point or execute the module from the trusted project root:

    bash
    python -m scripts.smyx_fish_gasping_ammonia_warning_analysis
    

    Ensure the project root is supplied through a controlled installation mechanism rather than inferred by traversing into /tmp.

  3. If path adjustment is unavoidable, calculate the exact project root rather than ascending beyond it:

    python
    from pathlib import Path
    project_root = Path(__file__).resolve().parents[1]
    

    Before adding it, verify that the resolved directory is the expected project root and is not writable by untrusted users.

  4. Do not prepend shared or world-writable directories to sys.path. Reject paths such as /tmp, /var/tmp, or directories with unsafe ownership or write permissions.

  5. Install the Skill in a directory owned by the Agent account or an administrator, with write access denied to unrelated local users.

  6. Run Python in isolated mode where compatible, and use a dedicated virtual environment with explicitly installed dependencies to reduce ambient import-path influence.

  7. Add a regression test that resolves the calculated project root and fails if it points outside the Skill installation directory or into a world-writable location.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (67)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as on-device aquarium video symptom analysis, but the detected behavior indicates generic external API submission, job polling, file handling, and report retrieval instead of the claimed fish-specific logic. This is dangerous because users may unknowingly send sensitive media and trust medical-style alerts from an implementation that does not actually perform the described analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as on-device aquarium video symptom analysis, but the detected behavior indicates generic external API submission, job polling, file handling, and report retrieval instead of the claimed fish-specific logic. This is dangerous because users may unknowingly send sensitive media and trust medical-style alerts from an implementation that does not actually perform the described analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as on-device aquarium video symptom analysis, but the detected behavior indicates generic external API submission, job polling, file handling, and report retrieval instead of the claimed fish-specific logic. This is dangerous because users may unknowingly send sensitive media and trust medical-style alerts from an implementation that does not actually perform the described analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as on-device aquarium video symptom analysis, but the detected behavior indicates generic external API submission, job polling, file handling, and report retrieval instead of the claimed fish-specific logic. This is dangerous because users may unknowingly send sensitive media and trust medical-style alerts from an implementation that does not actually perform the described analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as on-device aquarium video symptom analysis, but the detected behavior indicates generic external API submission, job polling, file handling, and report retrieval instead of the claimed fish-specific logic. This is dangerous because users may unknowingly send sensitive media and trust medical-style alerts from an implementation that does not actually perform the described analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as on-device aquarium video symptom analysis, but the detected behavior indicates generic external API submission, job polling, file handling, and report retrieval instead of the claimed fish-specific logic. This is dangerous because users may unknowingly send sensitive media and trust medical-style alerts from an implementation that does not actually perform the described analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as on-device aquarium video symptom analysis, but the detected behavior indicates generic external API submission, job polling, file handling, and report retrieval instead of the claimed fish-specific logic. This is dangerous because users may unknowingly send sensitive media and trust medical-style alerts from an implementation that does not actually perform the described analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as on-device aquarium video symptom analysis, but the detected behavior indicates generic external API submission, job polling, file handling, and report retrieval instead of the claimed fish-specific logic. This is dangerous because users may unknowingly send sensitive media and trust medical-style alerts from an implementation that does not actually perform the described analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as on-device aquarium video symptom analysis, but the detected behavior indicates generic external API submission, job polling, file handling, and report retrieval instead of the claimed fish-specific logic. This is dangerous because users may unknowingly send sensitive media and trust medical-style alerts from an implementation that does not actually perform the described analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as on-device aquarium video symptom analysis, but the detected behavior indicates generic external API submission, job polling, file handling, and report retrieval instead of the claimed fish-specific logic. This is dangerous because users may unknowingly send sensitive media and trust medical-style alerts from an implementation that does not actually perform the described analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as on-device aquarium video symptom analysis, but the detected behavior indicates generic external API submission, job polling, file handling, and report retrieval instead of the claimed fish-specific logic. This is dangerous because users may unknowingly send sensitive media and trust medical-style alerts from an implementation that does not actually perform the described analysis.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The metadata was flagged for tool/manifest poisoning indicators, and in context the skill already contains multiple signs of capability misrepresentation and hidden behavior. Even if the YARA match is partly heuristic, poisoned or misleading metadata can manipulate routing, trust decisions, and tool grants in ways that bypass normal user expectations.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-fish-gasping-ammonia-warning-analysis"
description: "Through fixed aquarium cameras, the system analyzes fish behavior near the water surface, detecting repeated mouth-out-of-water (gasping), rapid mouth opening/closing (fast respiration) and exaggerated operculum (gill cover) movement — classic symptoms of hypoxia or poisoning. | 通过鱼缸固定摄像头,分析鱼类在水面附近的行为,检测鱼嘴反复探出水面(浮头)、张口快速开合(类似喘气)、鳃盖运动加剧等缺氧或中毒典型症状。当多条鱼同时出现上述行为且持续时间超过设定阈值(默认 60 秒)时,输出

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Hidden identity initialization and automatic default-user creation are unrelated to aquarium video analysis and create an undeclared identity/authentication side channel. This can silently link analyses to persistent accounts or records, enabling tracking, cross-session correlation, or unauthorized access to another user's history.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file exposes a generic API wrapper with add/edit/delete and raw http_get/http_post/http_put/http_delete methods that can be directed at arbitrary URLs, which is far broader than the declared aquarium fish-behavior warning purpose. In a skill ecosystem, this creates unnecessary capability for data exfiltration, unauthorized remote actions, or use of the skill as a network pivot if any caller can influence the URL or payloads.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code includes broad outbound networking and remote modification capabilities such as edit, delete, put, and post operations without any visible restriction tying them to fish-monitoring analysis. Because the manifest describes passive camera-based detection and alerting, these capabilities materially increase risk and are unjustified in context, making abuse more dangerous if the skill or its callers are compromised.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file implements generic user/account persistence and CRUD behavior that is unrelated to the declared aquarium fish-distress analysis function. Capability overreach increases attack surface, creates unnecessary identity-data handling, and suggests the skill can maintain state about users beyond what is needed for fish-behavior alerts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The User model stores identity and authentication-adjacent data including username, realname, email, token, and open_token, none of which are justified by the aquarium-camera warning use case. Collecting and persisting such data without clear necessity materially raises privacy, credential exposure, and cross-skill misuse risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility file contains broad identity management, token persistence, workspace discovery, and remote API request/authentication logic that is unrelated to the declared aquarium-camera warning skill. That mismatch is dangerous because installing or invoking a narrowly described analysis skill can silently introduce account creation, credential handling, and outbound service interactions far beyond user expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The request helper can auto-create or auto-register a user as a side effect of making an HTTP request, using local state or generated identifiers when no explicit identity is supplied. Silent identity creation is dangerous because it can bind users to remote accounts, persist tokens locally, and trigger undisclosed external interactions merely from normal skill execution.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares no explicit tool/permission scope even though the documented behavior and referenced scripts imply shell execution, filesystem access, network access, and local writes. This weakens containment and reviewability because an agent may grant broader capabilities than users expect for a camera-analysis skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documentation adds a cloud historical-report lookup feature that is materially different from simple visual analysis. Expanding scope to cloud report access increases data exposure and behavioral surprise, especially when users expect only local or direct video processing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The auto-trigger phrases for history lookup are broad enough to activate cloud report retrieval from loosely related user text. Overbroad triggers can cause unintended access to historical data or unexpected network actions without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill states that uploaded media will be automatically saved locally, but it does not prominently disclose retention, storage location, or privacy implications at the point of collection. Silent local persistence increases the risk of unnecessary retention of potentially sensitive video content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Automatic cloud API querying of historical reports is not necessary for the stated purpose of detecting fish distress from supplied footage and introduces extra network exfiltration and account-data access risk. Hidden or automatic remote lookups can expose user-associated report metadata without a clear need-to-know basis.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI exposes --api-url and --api-key as if remote service configuration is part of the tool's behavior, but analyze_video discards api_url, api_key, and output_level and simply calls skill.get_output_analysis(input_path). This creates a mismatch between the apparent documented interface and the actual implemented behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2