T09 · Insecure Skill Coding Practices
- Location
skills/smyx_common/scripts/config.yaml:15- Finding
Authentication Tokens, Identity Data, and Media Are Transmitted over Cleartext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a cloud-based plant media analyzer, but it silently manages identities and tokens and uses insecure token storage/transport that users should review before installing.
Install only after reviewing the publisher and being comfortable with plant images/videos, URLs, and report history being sent to a remote service and tied to an internal identity. Prefer a version that defaults to HTTPS production endpoints, avoids plaintext token storage, documents retention/deletion behavior, and asks for clear consent before cloud analysis or history lookup.
skills/smyx_common/scripts/config.yaml:15Authentication Tokens, Identity Data, and Media Are Transmitted over Cleartext HTTP
skills/smyx_common/scripts/util.py:586Bearer Tokens Are Persisted in Plaintext in a Shared Workspace Database
This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.
This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.
This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.
This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.
This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.
This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.
This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.
This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.
This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.
This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.
This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.
This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.
This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
---
name: "smyx-leaf-curling-scorch-diagnosis-analysis"
description: "Using agricultural cameras to capture high-resolution images of plant leaves, AI vision techniques detect leaf curling direction (up-curling or down-curling) and the distribution of leaf-margin scorch (old vs new leaves, tip vs margin). | 通过农业摄像头拍摄植物叶片的高清图像,利用AI视觉分析技术检测叶片卷曲方向(上卷或下卷)、焦边(叶缘干枯)的分布特征(老叶/新叶、叶尖/叶缘),并可结合土壤湿度传感器数据(可选),综合判断卷叶/焦边的主要原因(干旱胁迫、病害如白粉病/病毒�
The manifest describes diagnosis from agricultural camera images of plant leaves, optionally combined with soil-moisture sensor data. In contrast, this code explicitly requires a local video path or network video URL, sets a "videoUrl" parameter, and uploads the file as a video-oriented input, which is a material mismatch in the skill's implemented modality and behavior.
The implementation materially contradicts the declared skill purpose: it accepts MP4/video URLs, lists video history, and invokes a generic video-analysis backend rather than performing plant leaf curl/scorch diagnosis. This mismatch is dangerous because users and higher-level agents may grant inputs, permissions, or trust based on the manifest, while the code actually routes different data to a separate analysis workflow, creating a deceptive capability and data-handling boundary.
The User model stores token and open_token fields, along with username, realname, email, and other identity attributes, despite the skill being described as an agricultural diagnosis tool. Persisting authentication or session tokens in a local shared SQLite database is dangerous because compromise of the workspace or adjacent skills could expose credentials and enable account takeover or cross-skill impersonation.
The code silently derives or creates an open-id by reading local files, reusing local database users, or generating and storing a new platform identity. For a crop-diagnosis skill, auto-provisioning identities without user awareness is unnecessary and dangerous because it creates hidden accounts and ties local execution to external platform identities.
This utility layer performs remote login/registration, token acquisition, token persistence, and authenticated HTTP requests that are unrelated to the declared leaf-image diagnosis functionality. In the context of an agricultural vision skill, this hidden account and network behavior materially increases the attack surface and can enable undisclosed identity use, tracking, or unauthorized service access.
The request flow automatically logs in or registers a user, populates tokens, and sends identifiers such as openId, mobile/username, and auth headers to remote services without any visible user-facing disclosure in this code. For a leaf-diagnosis skill, this hidden transmission is especially problematic because users would not reasonably expect account-linked network activity from image analysis utilities.
The skill declares no explicit tool scope while the manifest instructs shell execution, local file handling, outbound network access, and implicit identity handling. Without an allowlist or permissions block, reviewers and downstream runtimes cannot easily constrain what the skill is allowed to do, increasing the risk of overbroad execution and data exfiltration.
The user-facing description does not clearly warn that uploaded files, URLs, and report queries may be transmitted to cloud services and linked to an internal identity. This is a meaningful privacy and consent problem because users may reasonably believe they are using a local agricultural analysis tool rather than a remote account-linked service.
The default trigger activates on essentially any plant-leaf image or video, which can cause the skill to run in contexts where the user did not intend cloud analysis, file saving, or report generation. Because this skill also appears to involve uploads and identity-linked processing, overbroad triggering increases the chance of accidental data disclosure.
Automatic triggering of history-report queries from broad natural-language phrases can expose prior records without a strong confirmation step. In a skill that internally associates reports with an identity, this raises the risk of unintended retrieval and display of sensitive historical data.
The workflow states that uploaded attachments are automatically saved locally, but the manifest gives no clear user warning about persistence, storage location, or retention. Silent local storage increases the risk of sensitive image retention, later unauthorized access, and mismatch with user expectations.
Detected: suspicious.install_untrusted_source