Back to skill

Security audit

Neonatal Jaundice Screening (Facial Skin Color) | 新生儿黄疸筛查(面部皮肤颜色)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a neonatal screening helper, but it uploads sensitive infant media to cloud services and silently creates or reuses persistent identities and tokens with insufficient user-facing control.

Review carefully before installing. Use only if you are comfortable sending newborn face images or video URLs and report queries to the configured LifeEmergence cloud services, and ask the publisher for clear answers on guardian consent, retention, deletion, token storage, account binding, and whether local identity data is encrypted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine sensitive medical-image intake with network requests, authentication material, remote user/open-id resolution, and local user-related storage, none of which are clearly reflected in the plain-language purpose. In context, this is especially dangerous because it can enable hidden identity binding, data exfiltration, and broad backend interaction under the pretense of a simple newborn-screening tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine sensitive medical-image intake with network requests, authentication material, remote user/open-id resolution, and local user-related storage, none of which are clearly reflected in the plain-language purpose. In context, this is especially dangerous because it can enable hidden identity binding, data exfiltration, and broad backend interaction under the pretense of a simple newborn-screening tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine sensitive medical-image intake with network requests, authentication material, remote user/open-id resolution, and local user-related storage, none of which are clearly reflected in the plain-language purpose. In context, this is especially dangerous because it can enable hidden identity binding, data exfiltration, and broad backend interaction under the pretense of a simple newborn-screening tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine sensitive medical-image intake with network requests, authentication material, remote user/open-id resolution, and local user-related storage, none of which are clearly reflected in the plain-language purpose. In context, this is especially dangerous because it can enable hidden identity binding, data exfiltration, and broad backend interaction under the pretense of a simple newborn-screening tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine sensitive medical-image intake with network requests, authentication material, remote user/open-id resolution, and local user-related storage, none of which are clearly reflected in the plain-language purpose. In context, this is especially dangerous because it can enable hidden identity binding, data exfiltration, and broad backend interaction under the pretense of a simple newborn-screening tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine sensitive medical-image intake with network requests, authentication material, remote user/open-id resolution, and local user-related storage, none of which are clearly reflected in the plain-language purpose. In context, this is especially dangerous because it can enable hidden identity binding, data exfiltration, and broad backend interaction under the pretense of a simple newborn-screening tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine sensitive medical-image intake with network requests, authentication material, remote user/open-id resolution, and local user-related storage, none of which are clearly reflected in the plain-language purpose. In context, this is especially dangerous because it can enable hidden identity binding, data exfiltration, and broad backend interaction under the pretense of a simple newborn-screening tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine sensitive medical-image intake with network requests, authentication material, remote user/open-id resolution, and local user-related storage, none of which are clearly reflected in the plain-language purpose. In context, this is especially dangerous because it can enable hidden identity binding, data exfiltration, and broad backend interaction under the pretense of a simple newborn-screening tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine sensitive medical-image intake with network requests, authentication material, remote user/open-id resolution, and local user-related storage, none of which are clearly reflected in the plain-language purpose. In context, this is especially dangerous because it can enable hidden identity binding, data exfiltration, and broad backend interaction under the pretense of a simple newborn-screening tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine sensitive medical-image intake with network requests, authentication material, remote user/open-id resolution, and local user-related storage, none of which are clearly reflected in the plain-language purpose. In context, this is especially dangerous because it can enable hidden identity binding, data exfiltration, and broad backend interaction under the pretense of a simple newborn-screening tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine sensitive medical-image intake with network requests, authentication material, remote user/open-id resolution, and local user-related storage, none of which are clearly reflected in the plain-language purpose. In context, this is especially dangerous because it can enable hidden identity binding, data exfiltration, and broad backend interaction under the pretense of a simple newborn-screening tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to combine sensitive medical-image intake with network requests, authentication material, remote user/open-id resolution, and local user-related storage, none of which are clearly reflected in the plain-language purpose. In context, this is especially dangerous because it can enable hidden identity binding, data exfiltration, and broad backend interaction under the pretense of a simple newborn-screening tool.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-neonatal-jaundice-screening-analysis"
description: "Using a neonatal monitor or baby camera, the system captures high-resolution facial images of the newborn and uses AI visual analysis to detect sclera color (white in normal babies, yellow when jaundiced) and facial skin yellowness index (based on skin-color chromatic spaces, e.g., mapping the skin region to estimated clinical bilirubin levels). It outputs a jaundice-risk hint (low / medium / high risk). | 通过新生儿监护器或婴儿摄像头拍摄新生儿面部高清图像,利用AI视觉分析技术检测巩膜(眼白)的颜色(正常白色,黄疸时呈黄色)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script behavior materially diverges from the declared medical purpose: it implements generic video analysis and history retrieval rather than narrowly scoped neonatal jaundice screening. In a healthcare context, this mismatch is dangerous because users may trust the skill to process sensitive newborn data for a specific diagnostic aid while the code exposes broader, unspecified processing pathways.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The model stores authentication tokens together with personally identifying data such as username, real name, email, birthday, age, and sex, but the skill purpose is infant image analysis rather than identity management. In a healthcare-adjacent workflow, this unnecessary retention materially raises the impact of any database compromise and may expose sensitive personal and medical-adjacent information.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest describes local visual jaundice-risk analysis, but the code implements generic remote HTTP access, login flows, token management, and automatic request enrichment. This mismatch is dangerous because users and reviewers may expect local-only processing while the skill can send data and identifiers to external services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The utility automatically creates or reuses backend identities, logs into a remote service, and persists tokens locally. For a neonatal jaundice image-analysis skill, this is unrelated capability creep that can silently bind user activity to backend accounts and transmit identifiers without clear necessity or consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares broad operational behavior that implies shell, network, local file read/write, and environment access, but it does not declare any explicit tool scope or permission boundaries. In a medical skill handling infant images and cloud queries, this increases the risk of over-privileged execution, unintended data access, and misuse of local or remote resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow states that uploaded newborn images/videos may be automatically saved locally and that cloud history queries and network URL processing occur, but the main workflow does not clearly foreground transmission, retention, and storage risks. Because the data involves infant facial images and linked health reports, insufficient notice meaningfully increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code presents the command description, argument help text, and runtime status/error messages entirely in Chinese. The file does not offer an opt-in language selection or explain that the tool is intentionally limited to a Chinese-speaking context, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The CLI exposes a medically branded neonatal jaundice screening tool while still accepting a legacy 'pet_type' taxonomy of cat/dog/other. This mismatch can cause incorrect routing, model selection, or downstream handling, which is especially dangerous in a neonatal health context because users may rely on medically framed output that is actually processed under non-human categories.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple returned status and result strings are fixed in Chinese, such as the report header and export-link text. Because the file does not provide user opt-in, locale selection, or justification for a Chinese-only experience, this appears to violate the language/locale policy.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest frames the skill as analyzing facial images for sclera and skin yellowness, but this code explicitly requires a local video path or network video URL and submits it as videoUrl. That is a material behavior mismatch at the manifest level because the implemented input modality is broader and different from the described image-based scope.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2