Back to skill

Security audit

Infant Prone Sleeping Asphyxia Alert Skill | 婴儿趴睡窒息预警技能

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches a cloud infant-video analysis purpose, but it silently creates or reuses identities, performs remote login/registration, and persists tokens for sensitive child-monitoring data without enough user-facing control or privacy detail.

Review before installing. This skill sends infant sleep media or media URLs to lifeemergence.com cloud services, can query prior cloud reports, silently creates or reuses an internal user identity, and stores authentication tokens in a local SQLite database under the workspace data directory. Install only if that cloud processing and token persistence are acceptable for sensitive child/home footage, and prefer using it with explicit user confirmation before history lookups.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (67)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, automatic identity/open-id handling, registration/login, token use, and filesystem setup are materially different from the narrow infant-monitoring behavior users are led to expect. This is dangerous because it combines hidden identity processing and remote transmission with a false appearance of a dedicated baby-safety monitor.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

External HTTP communication, automatic identity/open-id handling, registration/login, token use, and filesystem setup are materially different from the narrow infant-monitoring behavior users are led to expect. This is dangerous because it combines hidden identity processing and remote transmission with a false appearance of a dedicated baby-safety monitor.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

External HTTP communication, automatic identity/open-id handling, registration/login, token use, and filesystem setup are materially different from the narrow infant-monitoring behavior users are led to expect. This is dangerous because it combines hidden identity processing and remote transmission with a false appearance of a dedicated baby-safety monitor.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

External HTTP communication, automatic identity/open-id handling, registration/login, token use, and filesystem setup are materially different from the narrow infant-monitoring behavior users are led to expect. This is dangerous because it combines hidden identity processing and remote transmission with a false appearance of a dedicated baby-safety monitor.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

External HTTP communication, automatic identity/open-id handling, registration/login, token use, and filesystem setup are materially different from the narrow infant-monitoring behavior users are led to expect. This is dangerous because it combines hidden identity processing and remote transmission with a false appearance of a dedicated baby-safety monitor.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

External HTTP communication, automatic identity/open-id handling, registration/login, token use, and filesystem setup are materially different from the narrow infant-monitoring behavior users are led to expect. This is dangerous because it combines hidden identity processing and remote transmission with a false appearance of a dedicated baby-safety monitor.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, automatic identity/open-id handling, registration/login, token use, and filesystem setup are materially different from the narrow infant-monitoring behavior users are led to expect. This is dangerous because it combines hidden identity processing and remote transmission with a false appearance of a dedicated baby-safety monitor.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, automatic identity/open-id handling, registration/login, token use, and filesystem setup are materially different from the narrow infant-monitoring behavior users are led to expect. This is dangerous because it combines hidden identity processing and remote transmission with a false appearance of a dedicated baby-safety monitor.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

External HTTP communication, automatic identity/open-id handling, registration/login, token use, and filesystem setup are materially different from the narrow infant-monitoring behavior users are led to expect. This is dangerous because it combines hidden identity processing and remote transmission with a false appearance of a dedicated baby-safety monitor.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, automatic identity/open-id handling, registration/login, token use, and filesystem setup are materially different from the narrow infant-monitoring behavior users are led to expect. This is dangerous because it combines hidden identity processing and remote transmission with a false appearance of a dedicated baby-safety monitor.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, automatic identity/open-id handling, registration/login, token use, and filesystem setup are materially different from the narrow infant-monitoring behavior users are led to expect. This is dangerous because it combines hidden identity processing and remote transmission with a false appearance of a dedicated baby-safety monitor.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, automatic identity/open-id handling, registration/login, token use, and filesystem setup are materially different from the narrow infant-monitoring behavior users are led to expect. This is dangerous because it combines hidden identity processing and remote transmission with a false appearance of a dedicated baby-safety monitor.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, automatic identity/open-id handling, registration/login, token use, and filesystem setup are materially different from the narrow infant-monitoring behavior users are led to expect. This is dangerous because it combines hidden identity processing and remote transmission with a false appearance of a dedicated baby-safety monitor.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file exposes generic add/edit/delete and arbitrary HTTP verb wrappers that are far broader than the skill’s declared purpose of infant suffocation warning analysis. In a narrowly scoped safety-monitoring skill, such general-purpose remote action capability increases the attack surface and could be reused by other components to send, modify, or delete remote data unrelated to infant safety.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file defines generic user-account persistence, including user identity records and related lookup/update behavior, which is materially outside the declared infant suffocation warning purpose. In a safety-monitoring skill, hidden or unnecessary account-management code increases the attack surface and creates unjustified collection and retention of personal data unrelated to the advertised function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The User model stores sensitive profile and authentication-related data including email, birthday, token, and open_token, none of which are clearly required for detecting prone sleeping, head covering, or airway occlusion. Collecting and mutating such data in a child-safety skill creates privacy and credential-handling risk, especially if the database is local, weakly protected, or reused across agents.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility file contains open-id resolution, credential discovery, local user lookup, and automatic account creation logic that is unrelated to the declared infant suffocation warning purpose. In a safety-monitoring skill, hidden identity provisioning and persistence materially increases risk because the skill can silently assume or create identities and prepare for backend access beyond what users would expect.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

When no identity is present, the code generates a synthetic default user, writes it to the local database, and then reuses it later. Silent creation of persistent identities is unrelated to infant safety monitoring and dangerous because it can establish backend-traceable accounts and durable local state without user knowledge or approval.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The HTTP client performs backend authentication, token loading, token refresh via re-login, and persistence of returned tokens/user records, none of which aligns with an infant sleep hazard detection skill's stated purpose. This broad remote access capability enables silent data transmission and account lifecycle actions, making the skill context more dangerous because users would reasonably expect local safety analysis, not background identity-backed API operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This request path sends usernames, open IDs, tenant data, skill metadata, and authentication tokens to remote services without any visible user-facing disclosure or opt-in. In a baby-safety alerting skill, hidden authenticated network transmission is especially concerning because the functional expectations are narrow and safety-focused, making undisclosed backend communication disproportionately risky.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents and encourages shell execution, file handling, network access, and local state manipulation, but it does not declare any explicit tool-scope restrictions such as allowed tools or permissions. This creates an overbroad execution surface where the agent may use more capabilities than the metadata communicates, increasing the risk of unintended command execution, data access, or exfiltration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The historical-report auto-trigger keywords are broad and may cause unintended cloud queries when users mention general history-related phrases. This can lead to unnecessary disclosure of sensitive prior infant-monitoring reports or accidental retrieval of another user's associated data if identity binding is weak.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill asks users to provide local files or remote URLs for analysis and states that API services will download network resources, but it does not prominently warn users that media may be transmitted to cloud services. In the context of infant sleep videos, this is privacy-sensitive because uploads may contain highly sensitive footage from inside a home and of a child.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
74% confidence
Finding

The file is largely bilingual, but the operational instructions and output formatting requirements are primarily prescribed in Chinese, including trigger phrases and reporting guidance, without explicitly offering the user a language preference. This may amount to a language/locale constraint that is not presented as optional or justified as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented APIs are for pet health analysis, which conflicts with the stated purpose of an infant suffocation warning skill. This kind of cross-domain mismatch can cause the skill to call or expose unrelated backend capabilities, leading to incorrect processing, data mishandling, or deployment of the wrong service in a safety-critical context.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2