Back to skill

Security audit

Leaf Aging Fall Prediction | 植物叶片老化/脱落预测

Security checks for vulnerabilities and agentic risk

Overview

This gardening analysis skill sends media and history requests to a remote service while silently creating or reusing a persistent account identity, so it needs user review before installation.

Install only if you are comfortable with plant images or video, URLs, and report history being processed by the publisher's remote service and linked to a persistent local/remote identity. Avoid using it for media that may contain people, private interiors, sensitive locations, or account data unless the publisher clarifies retention, deletion, and identity handling.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (61)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description omits that it performs authenticated external requests, local file and directory operations, workspace/environment discovery, identity creation/resolution, and token/login flows, while not implementing the promised plant-analysis pipeline. This combination of hidden identity, storage, and network behavior behind a benign gardening use case is especially dangerous because it can facilitate covert data collection and account linkage with low user suspicion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description omits that it performs authenticated external requests, local file and directory operations, workspace/environment discovery, identity creation/resolution, and token/login flows, while not implementing the promised plant-analysis pipeline. This combination of hidden identity, storage, and network behavior behind a benign gardening use case is especially dangerous because it can facilitate covert data collection and account linkage with low user suspicion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description omits that it performs authenticated external requests, local file and directory operations, workspace/environment discovery, identity creation/resolution, and token/login flows, while not implementing the promised plant-analysis pipeline. This combination of hidden identity, storage, and network behavior behind a benign gardening use case is especially dangerous because it can facilitate covert data collection and account linkage with low user suspicion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description omits that it performs authenticated external requests, local file and directory operations, workspace/environment discovery, identity creation/resolution, and token/login flows, while not implementing the promised plant-analysis pipeline. This combination of hidden identity, storage, and network behavior behind a benign gardening use case is especially dangerous because it can facilitate covert data collection and account linkage with low user suspicion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description omits that it performs authenticated external requests, local file and directory operations, workspace/environment discovery, identity creation/resolution, and token/login flows, while not implementing the promised plant-analysis pipeline. This combination of hidden identity, storage, and network behavior behind a benign gardening use case is especially dangerous because it can facilitate covert data collection and account linkage with low user suspicion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description omits that it performs authenticated external requests, local file and directory operations, workspace/environment discovery, identity creation/resolution, and token/login flows, while not implementing the promised plant-analysis pipeline. This combination of hidden identity, storage, and network behavior behind a benign gardening use case is especially dangerous because it can facilitate covert data collection and account linkage with low user suspicion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description omits that it performs authenticated external requests, local file and directory operations, workspace/environment discovery, identity creation/resolution, and token/login flows, while not implementing the promised plant-analysis pipeline. This combination of hidden identity, storage, and network behavior behind a benign gardening use case is especially dangerous because it can facilitate covert data collection and account linkage with low user suspicion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description omits that it performs authenticated external requests, local file and directory operations, workspace/environment discovery, identity creation/resolution, and token/login flows, while not implementing the promised plant-analysis pipeline. This combination of hidden identity, storage, and network behavior behind a benign gardening use case is especially dangerous because it can facilitate covert data collection and account linkage with low user suspicion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description omits that it performs authenticated external requests, local file and directory operations, workspace/environment discovery, identity creation/resolution, and token/login flows, while not implementing the promised plant-analysis pipeline. This combination of hidden identity, storage, and network behavior behind a benign gardening use case is especially dangerous because it can facilitate covert data collection and account linkage with low user suspicion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description omits that it performs authenticated external requests, local file and directory operations, workspace/environment discovery, identity creation/resolution, and token/login flows, while not implementing the promised plant-analysis pipeline. This combination of hidden identity, storage, and network behavior behind a benign gardening use case is especially dangerous because it can facilitate covert data collection and account linkage with low user suspicion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description omits that it performs authenticated external requests, local file and directory operations, workspace/environment discovery, identity creation/resolution, and token/login flows, while not implementing the promised plant-analysis pipeline. This combination of hidden identity, storage, and network behavior behind a benign gardening use case is especially dangerous because it can facilitate covert data collection and account linkage with low user suspicion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description omits that it performs authenticated external requests, local file and directory operations, workspace/environment discovery, identity creation/resolution, and token/login flows, while not implementing the promised plant-analysis pipeline. This combination of hidden identity, storage, and network behavior behind a benign gardening use case is especially dangerous because it can facilitate covert data collection and account linkage with low user suspicion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description omits that it performs authenticated external requests, local file and directory operations, workspace/environment discovery, identity creation/resolution, and token/login flows, while not implementing the promised plant-analysis pipeline. This combination of hidden identity, storage, and network behavior behind a benign gardening use case is especially dangerous because it can facilitate covert data collection and account linkage with low user suspicion.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The YARA hit indicates suspicious metadata poisoning characteristics in the skill manifest. While a metadata-only hit can be noisy, in this file it is reinforced by extensive description-behavior mismatch and hidden capability concerns, making the suspicious manifest content more concerning as a possible attempt to influence tooling or evade straightforward review.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-leaf-aging-fall-prediction-analysis"
description: "Using a fixed indoor camera to continuously capture leaf images of houseplants from the same angle every day, AI vision techniques detect leaf color changes (green → yellow → brown), loss of glossiness (reduced surface reflectance), and formation of the abscission zone at the petiole base (angle change). | 通过室内绿植固定摄像头连续采集叶片图像(每天同一角度),利用AI视觉分析技术检测叶片颜色变化(从绿到黄再到褐)、光泽度下降(叶面反光减弱)、叶柄基部离层形成(角度变化)等老化进程,并基�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a fixed indoor camera workflow that analyzes daily leaf images over time to detect senescence markers and predict leaf-drop risk 3–7 days ahead. In contrast, this function accepts arbitrary local or remote video input and forwards it to a generic analysis method without any leaf-specific, image-sequence, or forecasting logic, indicating the actual behavior is broader and different from the stated skill purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This is an active contradiction between the function documentation/comments and the actual code path. The documented behavior claims an external agent call, while the implementation does not perform that action at all.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This code reads an identity value from data/smyx-api-key.txt, resolves a current open-id, reuses local database user records, and generates persistent fallback identities. For a plant-image analysis skill, persistent cross-run identity creation and credential reuse are unnecessary and dangerous because they enable silent user tracking and cross-skill account linkage without a manifest-justified need.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The utility code performs account discovery, silent registration/login, token management, and automatic retry against remote APIs, which is unrelated to a leaf-aging prediction skill's stated purpose. This creates an unjustified identity and network-authentication capability that can silently provision or reuse accounts and send user-linked data off-device, materially expanding attack surface and privacy risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill declares broad operational behavior involving shell execution, local file handling, environment access, and network/API use, but does not define any explicit tool scope or permissions boundaries in the manifest. This weakens least-privilege controls and can allow the runtime to expose more capabilities than users or reviewers would reasonably expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The default trigger activates on broadly defined plant-image or video submissions, which can cause the skill to run in contexts where the user did not intend leaf-aging analysis. Overbroad activation increases the chance of unintended local saving, remote upload, or cloud history access for media that may contain more information than needed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow states that uploaded attachments are automatically saved locally, but this is not surfaced as a clear user-facing warning near input collection. Silent local persistence can expose sensitive media to unintended retention, backup, or other local-access risks, especially in shared or multi-tenant environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Historical report queries directly invoke cloud APIs, but the description does not clearly warn users that this is a remote data-access operation beyond local analysis. Without explicit disclosure, users may not realize their request triggers backend data retrieval tied to identity and potentially broader data exposure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script exposes a --list mode that retrieves prior analysis records by internal user identity (open_id), which is outside the stated leaf-aging prediction purpose. Even though the ID is not directly prompted in help text, the code resolves and uses internal identity state, creating an unnecessary data-access surface that could disclose historical analysis data if invoked in an unintended context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code initializes and uses an internal user identifier via OpenIdUtil.resolve_current_open_id(...) despite the core function being local/URL-based plant-image analysis. Binding analysis behavior to an undisclosed internal identity increases privacy risk and can enable cross-user data access or tracking if the surrounding utilities infer identity from environment or session state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs hidden internal identity resolution and comments that the user is not required to input it and it should not be shown in help output. Concealing identity handling is dangerous because users and integrators cannot accurately assess what account context will be used, increasing the risk of silent data association, unauthorized record retrieval, and privacy violations.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2