Back to skill

Security audit

Package Detection Skill | 包裹检测技能

Security checks for vulnerabilities and agentic risk

Overview

This package-detection skill performs the advertised media analysis, but it also silently creates or reuses an identity, stores account tokens locally, and retrieves cloud history with limited user control.

Review this before installing if you are comfortable with surveillance media being sent to the publisher's cloud service, cloud report history being queried automatically, and a local workspace database storing generated user identity and tokens. Prefer installing only if you trust the service provider and can accept account-scoped cloud processing for the media involved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (59)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of local file access, environment discovery, identity generation/persistence, database storage, outbound HTTP, and token/login handling is significantly broader than the declared package-detection role. In a surveillance-media workflow, that breadth enables collection, persistence, and transmission of sensitive user and media data under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of local file access, environment discovery, identity generation/persistence, database storage, outbound HTTP, and token/login handling is significantly broader than the declared package-detection role. In a surveillance-media workflow, that breadth enables collection, persistence, and transmission of sensitive user and media data under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of local file access, environment discovery, identity generation/persistence, database storage, outbound HTTP, and token/login handling is significantly broader than the declared package-detection role. In a surveillance-media workflow, that breadth enables collection, persistence, and transmission of sensitive user and media data under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of local file access, environment discovery, identity generation/persistence, database storage, outbound HTTP, and token/login handling is significantly broader than the declared package-detection role. In a surveillance-media workflow, that breadth enables collection, persistence, and transmission of sensitive user and media data under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of local file access, environment discovery, identity generation/persistence, database storage, outbound HTTP, and token/login handling is significantly broader than the declared package-detection role. In a surveillance-media workflow, that breadth enables collection, persistence, and transmission of sensitive user and media data under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of local file access, environment discovery, identity generation/persistence, database storage, outbound HTTP, and token/login handling is significantly broader than the declared package-detection role. In a surveillance-media workflow, that breadth enables collection, persistence, and transmission of sensitive user and media data under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of local file access, environment discovery, identity generation/persistence, database storage, outbound HTTP, and token/login handling is significantly broader than the declared package-detection role. In a surveillance-media workflow, that breadth enables collection, persistence, and transmission of sensitive user and media data under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of local file access, environment discovery, identity generation/persistence, database storage, outbound HTTP, and token/login handling is significantly broader than the declared package-detection role. In a surveillance-media workflow, that breadth enables collection, persistence, and transmission of sensitive user and media data under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of local file access, environment discovery, identity generation/persistence, database storage, outbound HTTP, and token/login handling is significantly broader than the declared package-detection role. In a surveillance-media workflow, that breadth enables collection, persistence, and transmission of sensitive user and media data under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of local file access, environment discovery, identity generation/persistence, database storage, outbound HTTP, and token/login handling is significantly broader than the declared package-detection role. In a surveillance-media workflow, that breadth enables collection, persistence, and transmission of sensitive user and media data under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of local file access, environment discovery, identity generation/persistence, database storage, outbound HTTP, and token/login handling is significantly broader than the declared package-detection role. In a surveillance-media workflow, that breadth enables collection, persistence, and transmission of sensitive user and media data under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The overview text describes chronic-disease patient monitoring, including sensitive health-related symptom analysis, inside a package-detection skill. This cross-domain mismatch is a major red flag because it suggests copy-paste contamination or hidden health-analysis functionality, which could misroute sensitive medical or surveillance data and invalidate user expectations and compliance assumptions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The implementation is a generic media-analysis and reporting client that accepts arbitrary local files or remote video URLs, submits them for backend analysis, and returns/export reports. That behavior materially exceeds the declared package-detection purpose, creating a capability/intent mismatch that can mislead users and reviewers about what data is processed and what the skill can do.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file exposes broad generic CRUD and arbitrary HTTP helper methods that are not constrained to the declared package-detection purpose. In a skill meant for surveillance package detection, these wrappers can be repurposed to call unrelated backend endpoints, modify data, or access services beyond the intended scope, which significantly expands the attack surface and enables capability abuse if the skill or dependent code is compromised.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file defines a full user/account ORM model and DAO with username, realname, email, birthday, token, and open_token handling, which does not align with a package-detection skill's declared purpose. In context, unnecessary identity and token persistence broadens the data-collection surface and creates unjustified sensitive-data retention, making the mismatch a meaningful security/privacy issue rather than a harmless architectural choice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The User model stores token and open_token alongside personal profile fields, yet the advertised functionality is only package detection in surveillance footage. Retaining authentication artifacts and user profile data without clear necessity increases the blast radius of local compromise and raises strong suspicion of over-collection in a context where such data should be unnecessary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code automatically derives or creates persistent user identities, including reading from a workspace file and creating fallback users in a local database, then stores that identity for later API use. For a package-detection skill this is unjustified and risky because it can create hidden accounts, bind activity to opaque identities, and enable downstream authenticated actions without explicit operator awareness.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility module goes far beyond package detection by implementing identity resolution, user/account provisioning, token persistence, and authenticated remote API communication. In the context of a surveillance package-detection skill, that mismatch is dangerous because it silently expands the skill's privilege and data-exfiltration surface without an evident functional need.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares broad behavior that implies shell execution, file access, environment access, and network use, but it does not declare any explicit tool scope or permissions. This creates a transparency and least-privilege problem: a caller or review system cannot easily constrain what the skill is allowed to do, increasing the risk of unexpected file, network, or command execution during use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description omits that user-provided media and related data may be transmitted to cloud services and that remote reports may be retrieved. This lack of disclosure undermines informed consent and is particularly sensitive here because the skill operates on surveillance images and videos that may contain personal or location-sensitive information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill expands from package detection into automatic cloud history-report querying, which introduces additional remote data access and potential privacy exposure beyond the core purpose. Automatic retrieval behavior is especially risky in surveillance contexts because historical reports may contain sensitive media-derived metadata and users may not realize the skill is accessing cloud records on trigger keywords alone.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Overly broad trigger keywords for history-report queries can cause unintended activation of remote data retrieval. In practice, benign user phrasing may accidentally cause cloud report listing, exposing sensitive historical records or causing the system to perform unanticipated data access actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states that uploaded attachments are automatically saved locally but does not present this as a user-facing warning. Silent local persistence of surveillance media increases the risk of accidental retention, unauthorized local access, or later reuse beyond the user's expectation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script initializes an internal user identity via OpenIdUtil.resolve_current_open_id() even though the open-id parameter is hidden from normal help output and the comment explicitly states the user is not required to input it or see it. That creates a privacy and authorization risk because analysis requests and list retrieval may be bound to a hidden identity context without clear disclosure or user consent, which is especially sensitive in a surveillance/package-detection skill handling potentially sensitive event history.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2