Back to skill

Security audit

Flowering Date Prediction | 开花植物花期预测

Security checks for vulnerabilities and agentic risk

Overview

This skill is a cloud media-analysis tool presented as flower-date prediction, but it silently manages user identities and persists tokens locally.

Install only if you are comfortable sending plant media or URLs to the configured cloud service and allowing the skill to silently create/reuse an identity, cache tokens in the workspace data directory, and retrieve cloud report history. The publisher should align the docs and code, disclose identity/token retention, and make history access explicitly user-confirmed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (64)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The implementation reportedly performs authenticated network requests, reads/writes local workspace files including API-key material, resolves and persists user identities, and manages tokens and environment-specific directories—far beyond a simple bloom-date predictor. In this context, the mismatch is particularly dangerous because the skill’s agricultural framing can obscure credential handling, identity correlation, and external data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The implementation reportedly performs authenticated network requests, reads/writes local workspace files including API-key material, resolves and persists user identities, and manages tokens and environment-specific directories—far beyond a simple bloom-date predictor. In this context, the mismatch is particularly dangerous because the skill’s agricultural framing can obscure credential handling, identity correlation, and external data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The implementation reportedly performs authenticated network requests, reads/writes local workspace files including API-key material, resolves and persists user identities, and manages tokens and environment-specific directories—far beyond a simple bloom-date predictor. In this context, the mismatch is particularly dangerous because the skill’s agricultural framing can obscure credential handling, identity correlation, and external data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The implementation reportedly performs authenticated network requests, reads/writes local workspace files including API-key material, resolves and persists user identities, and manages tokens and environment-specific directories—far beyond a simple bloom-date predictor. In this context, the mismatch is particularly dangerous because the skill’s agricultural framing can obscure credential handling, identity correlation, and external data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The implementation reportedly performs authenticated network requests, reads/writes local workspace files including API-key material, resolves and persists user identities, and manages tokens and environment-specific directories—far beyond a simple bloom-date predictor. In this context, the mismatch is particularly dangerous because the skill’s agricultural framing can obscure credential handling, identity correlation, and external data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The implementation reportedly performs authenticated network requests, reads/writes local workspace files including API-key material, resolves and persists user identities, and manages tokens and environment-specific directories—far beyond a simple bloom-date predictor. In this context, the mismatch is particularly dangerous because the skill’s agricultural framing can obscure credential handling, identity correlation, and external data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The implementation reportedly performs authenticated network requests, reads/writes local workspace files including API-key material, resolves and persists user identities, and manages tokens and environment-specific directories—far beyond a simple bloom-date predictor. In this context, the mismatch is particularly dangerous because the skill’s agricultural framing can obscure credential handling, identity correlation, and external data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The implementation reportedly performs authenticated network requests, reads/writes local workspace files including API-key material, resolves and persists user identities, and manages tokens and environment-specific directories—far beyond a simple bloom-date predictor. In this context, the mismatch is particularly dangerous because the skill’s agricultural framing can obscure credential handling, identity correlation, and external data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The implementation reportedly performs authenticated network requests, reads/writes local workspace files including API-key material, resolves and persists user identities, and manages tokens and environment-specific directories—far beyond a simple bloom-date predictor. In this context, the mismatch is particularly dangerous because the skill’s agricultural framing can obscure credential handling, identity correlation, and external data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The implementation reportedly performs authenticated network requests, reads/writes local workspace files including API-key material, resolves and persists user identities, and manages tokens and environment-specific directories—far beyond a simple bloom-date predictor. In this context, the mismatch is particularly dangerous because the skill’s agricultural framing can obscure credential handling, identity correlation, and external data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The implementation reportedly performs authenticated network requests, reads/writes local workspace files including API-key material, resolves and persists user identities, and manages tokens and environment-specific directories—far beyond a simple bloom-date predictor. In this context, the mismatch is particularly dangerous because the skill’s agricultural framing can obscure credential handling, identity correlation, and external data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The implementation reportedly performs authenticated network requests, reads/writes local workspace files including API-key material, resolves and persists user identities, and manages tokens and environment-specific directories—far beyond a simple bloom-date predictor. In this context, the mismatch is particularly dangerous because the skill’s agricultural framing can obscure credential handling, identity correlation, and external data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The implementation reportedly performs authenticated network requests, reads/writes local workspace files including API-key material, resolves and persists user identities, and manages tokens and environment-specific directories—far beyond a simple bloom-date predictor. In this context, the mismatch is particularly dangerous because the skill’s agricultural framing can obscure credential handling, identity correlation, and external data transmission.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The manifest triggered a metadata-poisoning rule, and while the matched snippet alone is not conclusive, the skill already shows multiple signs of misleading or overbroad metadata relative to likely behavior. In combination with the many description-behavior mismatches, suspicious manifest content becomes more security-relevant because metadata is what reviewers and routing systems rely on to assign trust and permissions.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-flowering-date-prediction-analysis"
description: "AI-powered flowering-date prediction for ornamental/cut-flower plants. From fixed greenhouse cameras or drones, captures images of flower-bud developmental stages, combines environmental sensor data — cumulative temperature (Growing Degree Days, GDD) and accumulated light (PAR or daylight hours) — and uses a pre-trained phenology model to predict the full-bloom date within the next 3-7 days. Helps growers precisely schedule pollination, harvesting and tourism activities. Scenarios: smart-agriculture greenhouses, cut-flower production bases, botanical gardens, flower tourism p

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file claims to document a flowering-date prediction skill, but the API documentation instead references pet health analysis endpoints and scenario codes. This kind of cross-domain mismatch is dangerous because it can cause the agent or integrators to call the wrong backend, expose unrelated sensitive data, or unintentionally grant access to another service under the guise of this skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a narrowly scoped skill for predicting flowering dates within 3–7 days using flower-bud images and environmental sensor data. This file instead accepts arbitrary local or remote video input, submits it to a generic analysis API, polls for a report, and exposes a paginated list of past analysis reports, with no visible handling of flowering-stage features, GDD/PAR inputs, or bloom-date prediction logic.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes predicting flowering dates from flower-bud imagery plus environmental data such as GDD and PAR using a phenology model. This file instead presents itself and operates as a generic 'video analysis tool', accepting MP4 files or video URLs, listing video-analysis history, and delegating to video-analysis methods without any handling of flowering stages, sensor inputs, or bloom-date prediction.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The User model stores token, open_token, email, birthday, and other personal/profile fields, none of which are justified by a flowering-date prediction workflow. Collecting and persisting credentials and PII in a local SQLite database materially increases the impact of compromise and violates data minimization expectations for this skill context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code reads workspace identity data from local files, falls back to local database records, and auto-generates persistent user identities when none exist. For a greenhouse phenology predictor, silently establishing and persisting identities is unrelated to core functionality and can enable unauthorized tracking, account linkage, or background service enrollment.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares broad operational behavior—shell execution, network access, local file reads/writes, and environment-variable use—but does not constrain these capabilities via an explicit tool scope. In practice, this increases the blast radius of prompt or workflow abuse because the agent is instructed to run local commands and access local/cloud-backed data without a least-privilege boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The history-report trigger phrases are broad enough to activate cloud report retrieval on ordinary conversational requests, which can cause unintended access to prior records. Because the skill also ties history access to internal identity handling, accidental triggering could expose sensitive historical analysis data without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow instructs the agent to automatically save uploaded files locally without a clear notice about storage, retention, or access controls. Silent local persistence increases privacy and data-leak risk, especially for user-supplied media that may contain sensitive imagery or metadata.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest claims the skill combines images with environmental sensor data such as GDD and accumulated light to predict bloom date within 3–7 days. In this file, the analysis entrypoint accepts only an input path/URL and an unrelated pet_type, then forwards just the media path to skill.get_output_analysis, with no handling of temperature, light, or other phenology inputs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a plant flowering-date prediction skill using flower-bud imagery and environmental data, but the exposed interface uses a pet-type parameter with values cat, dog, and other, and a --list help string for 'pet health analysis'. This indicates the implemented behavior/interface was repurposed from an unrelated pet-analysis skill and does not semantically match the declared flowering-prediction purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script accepts and resolves a hidden internal user identifier via a suppressed CLI argument and also derives a current internal identity without clear disclosure. Hidden identity parameters can enable unauthorized access to another user's analysis history or actions if downstream authorization is weak, and the lack of transparency increases misuse risk in a multi-user environment.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2