Back to skill

Security audit

Visual Emotion Recognition Skill | 人体视觉情绪识别技能

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its cloud emotion-analysis purpose, but it silently creates or reuses an identity and stores authentication tokens for sensitive face/emotion report workflows.

Review before installing. Use this only if you are comfortable sending face images/videos or URLs and emotion-analysis reports to the lifeemergence cloud service, and with the skill creating/reusing a local identity plus storing tokens in the workspace data database. Prefer a dedicated workspace and avoid regulated or highly sensitive media unless the service's retention and privacy terms are acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (67)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Reading local credential files, persisting user identities, performing login/registration, and making authenticated outbound requests are materially sensitive behaviors not reflected in the manifest's narrow emotion-recognition framing. In a biometric/mental-health skill, undisclosed credential and identity workflows create substantial privacy, secret-handling, and cross-account access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Reading local credential files, persisting user identities, performing login/registration, and making authenticated outbound requests are materially sensitive behaviors not reflected in the manifest's narrow emotion-recognition framing. In a biometric/mental-health skill, undisclosed credential and identity workflows create substantial privacy, secret-handling, and cross-account access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Reading local credential files, persisting user identities, performing login/registration, and making authenticated outbound requests are materially sensitive behaviors not reflected in the manifest's narrow emotion-recognition framing. In a biometric/mental-health skill, undisclosed credential and identity workflows create substantial privacy, secret-handling, and cross-account access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Reading local credential files, persisting user identities, performing login/registration, and making authenticated outbound requests are materially sensitive behaviors not reflected in the manifest's narrow emotion-recognition framing. In a biometric/mental-health skill, undisclosed credential and identity workflows create substantial privacy, secret-handling, and cross-account access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Reading local credential files, persisting user identities, performing login/registration, and making authenticated outbound requests are materially sensitive behaviors not reflected in the manifest's narrow emotion-recognition framing. In a biometric/mental-health skill, undisclosed credential and identity workflows create substantial privacy, secret-handling, and cross-account access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Reading local credential files, persisting user identities, performing login/registration, and making authenticated outbound requests are materially sensitive behaviors not reflected in the manifest's narrow emotion-recognition framing. In a biometric/mental-health skill, undisclosed credential and identity workflows create substantial privacy, secret-handling, and cross-account access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential files, persisting user identities, performing login/registration, and making authenticated outbound requests are materially sensitive behaviors not reflected in the manifest's narrow emotion-recognition framing. In a biometric/mental-health skill, undisclosed credential and identity workflows create substantial privacy, secret-handling, and cross-account access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential files, persisting user identities, performing login/registration, and making authenticated outbound requests are materially sensitive behaviors not reflected in the manifest's narrow emotion-recognition framing. In a biometric/mental-health skill, undisclosed credential and identity workflows create substantial privacy, secret-handling, and cross-account access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential files, persisting user identities, performing login/registration, and making authenticated outbound requests are materially sensitive behaviors not reflected in the manifest's narrow emotion-recognition framing. In a biometric/mental-health skill, undisclosed credential and identity workflows create substantial privacy, secret-handling, and cross-account access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential files, persisting user identities, performing login/registration, and making authenticated outbound requests are materially sensitive behaviors not reflected in the manifest's narrow emotion-recognition framing. In a biometric/mental-health skill, undisclosed credential and identity workflows create substantial privacy, secret-handling, and cross-account access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential files, persisting user identities, performing login/registration, and making authenticated outbound requests are materially sensitive behaviors not reflected in the manifest's narrow emotion-recognition framing. In a biometric/mental-health skill, undisclosed credential and identity workflows create substantial privacy, secret-handling, and cross-account access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential files, persisting user identities, performing login/registration, and making authenticated outbound requests are materially sensitive behaviors not reflected in the manifest's narrow emotion-recognition framing. In a biometric/mental-health skill, undisclosed credential and identity workflows create substantial privacy, secret-handling, and cross-account access risk.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "human-emotion-recognition-analysis"
description: "Uses visual AI on frontal faces to recognize multi-dimensional emotions like happiness, sadness, depression, calmness, anger, surprise, and fear in real-time. Supports emotion intensity quantification and abnormal emotion marking, suitable for human-computer interaction and mental health monitoring. | 人体视觉情绪识别技能,基于正面人脸视觉AI实时识别快乐、悲伤、抑郁、平静、愤怒、惊讶、恐惧等多维度情绪状态,支持情绪强度量化与异常情绪标记,适配人机交互、心理健康监测场景"
version: "1.0.17"
license: "MI

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill directs cloud API access for historical reports without clear disclosure that highly sensitive biometric and mental-health-related data may be transmitted to or retrieved from a remote service. Remote handling of face-derived emotional-state reports materially increases confidentiality and regulatory risk if users are not informed and consenting.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest claims a narrowly scoped capability: real-time visual emotion recognition on frontal human faces with emotion intensity and abnormal-emotion marking. In this file, the user-facing behavior is only 'video analysis' and listing prior analyses, with no code-level indication of face detection, emotion categories, intensity scoring, abnormal-emotion labeling, or real-time processing; instead it forwards arbitrary video input to generic analysis methods.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file exposes a generic API wrapper with arbitrary outbound HTTP methods (GET/POST/PUT/DELETE) and generic CRUD helpers that are far broader than the stated purpose of facial emotion recognition. In a skill context, this creates an unnecessary capability to send, modify, or delete remote resources, increasing the risk of data exfiltration, unauthorized side effects, or use of the skill as a general network proxy if higher-level inputs are user-controlled.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The add, edit, and delete methods provide generic remote resource modification capability without any visible restriction to emotion-analysis operations or approved targets. In a skill whose manifest describes analysis functionality, write/delete network actions are over-privileged and could be abused to alter external systems, especially if URLs or payloads are influenced by callers.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The User model stores token and open_token fields, which are authentication-like secrets, yet the skill description gives no justification for handling credentials. Persisting such tokens in a local SQLite database materially raises account-compromise risk if the workspace is accessed, copied, or backed up insecurely.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This utility provisions and persists default user identities and reads identity material from a workspace file, behavior unrelated to the stated emotion-recognition purpose. That creates hidden account state, enables silent identity reuse across sessions, and expands the skill's privilege and data-handling footprint without user awareness or clear necessity.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The HTTP layer silently performs account login/registration, token retrieval, token caching, and authenticated API calls, which is materially beyond an emotion-analysis skill's declared function. This allows the skill to create or reuse external identities and transmit authentication-linked data off-host, increasing the risk of unauthorized external service interaction and opaque data flows.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The HTTP utility transmits identity and authentication-related fields such as openId, mobile/username equivalents, tokens, and account-linked metadata without a clear user-facing warning. In the context of an emotion-recognition skill, this is especially concerning because users would not reasonably expect biometric-adjacent analysis tooling to silently perform authenticated external communications.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares broad operational behavior involving shell execution, filesystem access, environment access, and network/API calls, but does not declare any corresponding tool scope or permissions boundary in the manifest. This creates a transparency and least-privilege problem: a reviewer or runtime may not understand the skill's true capabilities, increasing the chance of over-privileged execution and unsafe deployment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger rules activate on broad terms such as emotion recognition, mental health, or stress-related language, which can cause the skill to engage during ordinary conversation rather than explicit consent to analyze sensitive media. Because this skill concerns biometric and inferred mental-health data, accidental activation is more dangerous than in a generic utility skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

History-report trigger phrases are generic enough that a user asking to view reports could unintentionally invoke retrieval of sensitive past analysis records. In this context, those records may contain biometric-derived emotion inferences and links to prior media or reports, making unintended disclosure more serious.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that uploaded files are automatically saved locally, but does not clearly warn users about local storage, retention, or access controls. Since the files are face images/videos used for emotion and mental-health-related inference, silent local storage raises significant privacy and compliance concerns.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2