Back to skill

Security audit

Intelligent Outdoor Care Monitoring & Analysis Tool | 户外看护智能监测分析工具

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does the advertised outdoor image/video analysis, but it also silently creates or reuses persistent cloud identities and can mix report history across users in a shared workspace.

Install only if you are comfortable sending outdoor surveillance images, videos, or URLs to the configured LifeEmergence cloud services and with the skill keeping account/token state in the workspace data directory. Avoid shared workspaces unless identity isolation is fixed, because report history may be associated with a shared fallback account rather than the actual caller.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/outdoor_monitoring.py:40
Finding

Workspace-wide fallback identity permits cross-user access to monitoring reports

Content
View full analysis

Vulnerability Details

File Location: scripts/outdoor_monitoring.py:40, 55-60; skills/smyx_common/scripts/config.py:153-160; skills/smyx_common/scripts/util.py:414-471; skills/smyx_analysis/scripts/skill.py:154-160
Vulnerability Type: Broken user isolation and improper authorization context
Risk Level: High

Vulnerable Code

scripts/outdoor_monitoring.py:40, 55-60:

python
parser.add_argument("--open-id", required=False, help=argparse.SUPPRESS)

...

# Initialize the internal user identity.
OpenIdUtil.resolve_current_open_id(
    args.open_id,
    use_current=bool(args.open_id)
)

if args.list:
    open_id = ConstantEnum.CURRENT__OPEN_ID
    result = show_analyze_list(open_id)
    print(result)
    exit(0)

skills/smyx_common/scripts/config.py:153-160:

python
openclaw_sender_open_id = os.environ.get("OPENCLAW_SENDER_OPEN_ID")
openclaw_sender_username = os.environ.get("OPENCLAW_SENDER_USERNAME")
feishu_open_id = os.environ.get("FEISHU_OPEN_ID")
if openclaw_sender_open_id:
    cls.CURRENT__OPEN_ID = openclaw_sender_open_id
if openclaw_sender_username:
    cls.CURRENT__USER_NAME = openclaw_sender_username

skills/smyx_common/scripts/util.py:414-471:

python
@classmethod
def get_api_key_file_open_id(cls):
    """Read the internal identity from data/smyx-api-key.txt."""
    api_key_path = os.path.join(
        cls.get_workspace_data_dir(),
        "smyx-api-key.txt"
    )
    try:
        if not os.path.exists(api_key_path):
            return None
        with open(api_key_path, "r", encoding="utf-8") as f:
            value = f.read().strip()
        return value or None
    except Exception as e:
        CommonUtil.trace_exception_stack(e)
    return None

@classmethod
def get_or_create_default_open_id(cls):
    from .dao import UserDao, User
    import uuid

    user_dao = UserDao()
    user = user_dao.get_fir
...[truncated 4878 chars]
Remediation
View remediation

Remediation Suggestions

  1. Preserve the authenticated upstream identity for every request. When OPENCLAW_SENDER_OPEN_ID or another trusted sender identity has been initialized, call identity resolution with use_current=True.

  2. Eliminate workspace-global fallback identities in multi-user deployments. If no authenticated identity is available, reject history retrieval and sensitive analysis submission rather than silently assigning all callers to one account.

  3. Pass the resolved identity explicitly through the complete call chain instead of relying on mutable process-global fields:

    python
    resolved_open_id = OpenIdUtil.resolve_current_open_id(
        args.open_id,
        use_current=True
    )
    result = show_analyze_list(resolved_open_id)
    
  4. Do not discard open_id in get_output_analysis_list(). Bind the authenticated principal to the server-side request and enforce report ownership on the remote API. Client-supplied identity fields must not be treated as proof of identity.

  5. Remove the hidden --open-id override from untrusted entry points, or require a trusted, authenticated invocation context before accepting it. Arbitrary identity selection must not alter the account used for authorization.

  6. Store tokens and account state per authenticated user or tenant rather than in a workspace-wide default database record. Include tenant and user identifiers in database lookup keys.

  7. Add integration tests with two distinct upstream users to verify that:

    • Each analysis is associated with the correct user.
    • Each history query returns only that user’s reports.
    • Missing identity fails closed.
    • A caller cannot select another user through --open-id.
  8. Review and migrate reports already associated with the shared fallback account. Existing mixed records should be reassigned where ownership can be established or restricted until ownership is resolved.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (52)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported behavior includes reading local identity files, creating or reusing local user identities, persisting them, performing login/registration, token management, and authenticated remote requests—far beyond the stated batch image-analysis purpose. This is especially dangerous because it introduces credential, identity, and long-lived account linkage risks hidden behind a seemingly simple media-analysis skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported behavior includes reading local identity files, creating or reusing local user identities, persisting them, performing login/registration, token management, and authenticated remote requests—far beyond the stated batch image-analysis purpose. This is especially dangerous because it introduces credential, identity, and long-lived account linkage risks hidden behind a seemingly simple media-analysis skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported behavior includes reading local identity files, creating or reusing local user identities, persisting them, performing login/registration, token management, and authenticated remote requests—far beyond the stated batch image-analysis purpose. This is especially dangerous because it introduces credential, identity, and long-lived account linkage risks hidden behind a seemingly simple media-analysis skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported behavior includes reading local identity files, creating or reusing local user identities, persisting them, performing login/registration, token management, and authenticated remote requests—far beyond the stated batch image-analysis purpose. This is especially dangerous because it introduces credential, identity, and long-lived account linkage risks hidden behind a seemingly simple media-analysis skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported behavior includes reading local identity files, creating or reusing local user identities, persisting them, performing login/registration, token management, and authenticated remote requests—far beyond the stated batch image-analysis purpose. This is especially dangerous because it introduces credential, identity, and long-lived account linkage risks hidden behind a seemingly simple media-analysis skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported behavior includes reading local identity files, creating or reusing local user identities, persisting them, performing login/registration, token management, and authenticated remote requests—far beyond the stated batch image-analysis purpose. This is especially dangerous because it introduces credential, identity, and long-lived account linkage risks hidden behind a seemingly simple media-analysis skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported behavior includes reading local identity files, creating or reusing local user identities, persisting them, performing login/registration, token management, and authenticated remote requests—far beyond the stated batch image-analysis purpose. This is especially dangerous because it introduces credential, identity, and long-lived account linkage risks hidden behind a seemingly simple media-analysis skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported behavior includes reading local identity files, creating or reusing local user identities, persisting them, performing login/registration, token management, and authenticated remote requests—far beyond the stated batch image-analysis purpose. This is especially dangerous because it introduces credential, identity, and long-lived account linkage risks hidden behind a seemingly simple media-analysis skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported behavior includes reading local identity files, creating or reusing local user identities, persisting them, performing login/registration, token management, and authenticated remote requests—far beyond the stated batch image-analysis purpose. This is especially dangerous because it introduces credential, identity, and long-lived account linkage risks hidden behind a seemingly simple media-analysis skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported behavior includes reading local identity files, creating or reusing local user identities, persisting them, performing login/registration, token management, and authenticated remote requests—far beyond the stated batch image-analysis purpose. This is especially dangerous because it introduces credential, identity, and long-lived account linkage risks hidden behind a seemingly simple media-analysis skill.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "outdoor-monitoring-analysis"
description: "Detects targets such as people, vehicles, non-motorized vehicles, and pets within target areas; supports batch image analysis, suitable for outdoor surveillance scenarios like courtyards, orchards, and farms. | 户外看护智能监测分析技能,检测目标区域内的人、车、非机动车、宠物等目标,支持批量图片分析,适用于庭院、果园、养殖场等户外区域看护场景"
version: "1.0.17"
license: "MIT-0"
---

# 🏞️ Intelligent Outdoor Care Monitoring & Analysis Tool | 户外看护智能监测分析工具
> **智能分析中枢** · 图片

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation performs video analysis and exposes a history-listing capability, while the skill metadata claims batch image analysis for outdoor monitoring. This mismatch is security-relevant because users, policy engines, or reviewers may grant the skill permissions or trust assumptions appropriate for image processing, while the code processes different media and accesses historical analysis data, expanding the actual capability surface beyond what was disclosed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility layer automatically resolves identities, provisions accounts, retrieves tokens, and persists authentication material locally, which is unrelated to the advertised outdoor image-analysis function. In context, that hidden identity management greatly increases risk because using the skill can silently create or reuse accounts and bind requests to a persistent user identity without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The helper silently performs a phone-login/register API call with register=1 and silent=1, meaning it can create or retrieve an account automatically. That is dangerous because it establishes remote identity and token state without informed consent, and it is unrelated to the declared purpose of outdoor monitoring analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The request wrapper attaches user identifiers and authentication headers, then transmits them over network requests without clear user disclosure. In this skill context, that is especially concerning because the manifest describes target detection, not account-linked telemetry or secret-bearing API activity, so users would not reasonably expect identity/token transmission.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises and instructs use of shell, filesystem, environment, and network-capable scripts but does not declare any explicit tool scope or permissions boundaries. In an agent environment, this increases the chance of over-broad execution and makes it harder to constrain what the skill can access if triggered on untrusted input.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The default trigger is broad enough to activate on many ordinary requests involving outdoor images or videos, increasing the likelihood of accidental execution on sensitive surveillance media. Because the skill also has shell, file, and network implications, over-triggering materially raises privacy and unauthorized-processing risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill states that uploaded attachments are automatically saved locally, but the documentation does not prominently warn users about this retention behavior or its privacy implications. For surveillance imagery and videos, silent local persistence can create unnecessary exposure of sensitive personal and property data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation says the API service will automatically download supplied network URLs but does not warn about privacy, provenance, or server-side retrieval risks. This can expose internal or sensitive URLs, enable unintended third-party fetches, or cause users to assume content stays local when it is actually transmitted to remote infrastructure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script exposes a hidden history-listing capability via --list and an internal open-id flow that is not aligned with the stated purpose of analyzing supplied images or videos. Because the listing uses an internal identity value and suppresses normal user-facing disclosure, it risks unauthorized access to prior analysis records or metadata if invoked in shared or automated environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The argument parser description and help strings are presented only in Chinese, and runtime status/error messages are also hardcoded in Chinese. This enforces a specific language for interaction without offering a language choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code initializes an internal user identity through OpenIdUtil.resolve_current_open_id(args.open_id, use_current=bool(args.open_id)) even though the parameter is hidden from normal help output. Hidden identity binding can cause actions to run under a non-obvious account context, enabling confusion, unintended data access, or privacy violations when operators do not realize identity resolution is occurring.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill emits fixed Chinese strings such as 分析报告结构化结果 and 获取报告导出图片链接, and other user-facing messages in Chinese throughout the file. There is no indication that the user can opt into this locale or that the skill is explicitly limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2