Back to skill

Security audit

Leaf Curling & Margin Scorch Diagnosis | 植物卷叶/焦边识别(干旱/病害)

Security checks for vulnerabilities and agentic risk

Overview

The skill is a cloud-based plant media analyzer, but it silently manages identities and tokens and uses insecure token storage/transport that users should review before installing.

Install only after reviewing the publisher and being comfortable with plant images/videos, URLs, and report history being sent to a remote service and tied to an internal identity. Prefer a version that defaults to HTTPS production endpoints, avoids plaintext token storage, documents retention/deletion behavior, and asks for clear consent before cloud analysis or history lookup.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/config.yaml:15
Finding

Authentication Tokens, Identity Data, and Media Are Transmitted over Cleartext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smyx_common/scripts/util.py:586
Finding

Bearer Tokens Are Persisted in Plaintext in a Shared Workspace Database

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (56)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is the strongest mismatch finding: the skill reportedly performs authenticated outbound HTTP requests, manages tokens and identities, reads/writes local workspace files, and retries authorization flows, while providing no visible plant-analysis logic. In context, that means the real security-sensitive behavior is cloud account and file handling, not agriculture diagnostics, making the undeclared trust boundary especially dangerous.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-leaf-curling-scorch-diagnosis-analysis"
description: "Using agricultural cameras to capture high-resolution images of plant leaves, AI vision techniques detect leaf curling direction (up-curling or down-curling) and the distribution of leaf-margin scorch (old vs new leaves, tip vs margin). | 通过农业摄像头拍摄植物叶片的高清图像,利用AI视觉分析技术检测叶片卷曲方向(上卷或下卷)、焦边(叶缘干枯)的分布特征(老叶/新叶、叶尖/叶缘),并可结合土壤湿度传感器数据(可选),综合判断卷叶/焦边的主要原因(干旱胁迫、病害如白粉病/病毒�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes diagnosis from agricultural camera images of plant leaves, optionally combined with soil-moisture sensor data. In contrast, this code explicitly requires a local video path or network video URL, sets a "videoUrl" parameter, and uploads the file as a video-oriented input, which is a material mismatch in the skill's implemented modality and behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The implementation materially contradicts the declared skill purpose: it accepts MP4/video URLs, lists video history, and invokes a generic video-analysis backend rather than performing plant leaf curl/scorch diagnosis. This mismatch is dangerous because users and higher-level agents may grant inputs, permissions, or trust based on the manifest, while the code actually routes different data to a separate analysis workflow, creating a deceptive capability and data-handling boundary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The User model stores token and open_token fields, along with username, realname, email, and other identity attributes, despite the skill being described as an agricultural diagnosis tool. Persisting authentication or session tokens in a local shared SQLite database is dangerous because compromise of the workspace or adjacent skills could expose credentials and enable account takeover or cross-skill impersonation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code silently derives or creates an open-id by reading local files, reusing local database users, or generating and storing a new platform identity. For a crop-diagnosis skill, auto-provisioning identities without user awareness is unnecessary and dangerous because it creates hidden accounts and ties local execution to external platform identities.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility layer performs remote login/registration, token acquisition, token persistence, and authenticated HTTP requests that are unrelated to the declared leaf-image diagnosis functionality. In the context of an agricultural vision skill, this hidden account and network behavior materially increases the attack surface and can enable undisclosed identity use, tracking, or unauthorized service access.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The request flow automatically logs in or registers a user, populates tokens, and sends identifiers such as openId, mobile/username, and auth headers to remote services without any visible user-facing disclosure in this code. For a leaf-diagnosis skill, this hidden transmission is especially problematic because users would not reasonably expect account-linked network activity from image analysis utilities.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares no explicit tool scope while the manifest instructs shell execution, local file handling, outbound network access, and implicit identity handling. Without an allowlist or permissions block, reviewers and downstream runtimes cannot easily constrain what the skill is allowed to do, increasing the risk of overbroad execution and data exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing description does not clearly warn that uploaded files, URLs, and report queries may be transmitted to cloud services and linked to an internal identity. This is a meaningful privacy and consent problem because users may reasonably believe they are using a local agricultural analysis tool rather than a remote account-linked service.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The default trigger activates on essentially any plant-leaf image or video, which can cause the skill to run in contexts where the user did not intend cloud analysis, file saving, or report generation. Because this skill also appears to involve uploads and identity-linked processing, overbroad triggering increases the chance of accidental data disclosure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Automatic triggering of history-report queries from broad natural-language phrases can expose prior records without a strong confirmation step. In a skill that internally associates reports with an identity, this raises the risk of unintended retrieval and display of sensitive historical data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow states that uploaded attachments are automatically saved locally, but the manifest gives no clear user warning about persistence, storage location, or retention. Silent local storage increases the risk of sensitive image retention, later unauthorized access, and mismatch with user expectations.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2