Back to skill

Security audit

Pet Body Condition & Health Analysis Skill | 宠物体态健康分析技能

Security checks for vulnerabilities and agentic risk

Overview

The skill offers pet health analysis, but it also quietly creates or reuses a user identity, sends media and identifiers to cloud services, stores auth tokens locally, and ships broad backend helper code.

Install only if you are comfortable with pet images or videos, URLs, generated user identifiers, and report history being sent to the configured cloud backend, and with local storage of account tokens in the workspace. The publisher should narrow triggers, separate history/account management from analysis, document identity and token retention clearly, and add explicit user consent before cloud history queries or media uploads.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (58)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The combination of identity resolution, local workspace reads/writes, authenticated external API requests, phone-login-like flows, and token storage goes far beyond a pet health analysis feature. In context, this is especially dangerous because users are likely to share media believing the skill is single-purpose, while hidden account and storage features can expose personal data or enable unauthorized backend access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of identity resolution, local workspace reads/writes, authenticated external API requests, phone-login-like flows, and token storage goes far beyond a pet health analysis feature. In context, this is especially dangerous because users are likely to share media believing the skill is single-purpose, while hidden account and storage features can expose personal data or enable unauthorized backend access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of identity resolution, local workspace reads/writes, authenticated external API requests, phone-login-like flows, and token storage goes far beyond a pet health analysis feature. In context, this is especially dangerous because users are likely to share media believing the skill is single-purpose, while hidden account and storage features can expose personal data or enable unauthorized backend access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of identity resolution, local workspace reads/writes, authenticated external API requests, phone-login-like flows, and token storage goes far beyond a pet health analysis feature. In context, this is especially dangerous because users are likely to share media believing the skill is single-purpose, while hidden account and storage features can expose personal data or enable unauthorized backend access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of identity resolution, local workspace reads/writes, authenticated external API requests, phone-login-like flows, and token storage goes far beyond a pet health analysis feature. In context, this is especially dangerous because users are likely to share media believing the skill is single-purpose, while hidden account and storage features can expose personal data or enable unauthorized backend access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of identity resolution, local workspace reads/writes, authenticated external API requests, phone-login-like flows, and token storage goes far beyond a pet health analysis feature. In context, this is especially dangerous because users are likely to share media believing the skill is single-purpose, while hidden account and storage features can expose personal data or enable unauthorized backend access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of identity resolution, local workspace reads/writes, authenticated external API requests, phone-login-like flows, and token storage goes far beyond a pet health analysis feature. In context, this is especially dangerous because users are likely to share media believing the skill is single-purpose, while hidden account and storage features can expose personal data or enable unauthorized backend access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of identity resolution, local workspace reads/writes, authenticated external API requests, phone-login-like flows, and token storage goes far beyond a pet health analysis feature. In context, this is especially dangerous because users are likely to share media believing the skill is single-purpose, while hidden account and storage features can expose personal data or enable unauthorized backend access.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "pet-body-health-analysis"
description: "Identifies obesity, emaciation, external injuries, skin abnormalities, and abnormal mental states, helping pet owners detect health issues promptly. | 宠物体态健康分析技能,识别肥胖、消瘦、外伤、皮肤异常、精神状态异常,帮助宠物主人及时发现宠物健康问题"
version: "1.0.17"
license: "MIT-0"
---

# 🐕 Pet Body Condition & Health Analysis Skill | 宠物体态健康分析技能
> **智能分析中枢** · 图片/视频智能分析 · 结构化报告 · 历史报告云端查询

---

## 🧭 技能概览 | Overview

| 模块 | 内容 |

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation materially diverges from the declared skill purpose: instead of pet body-health assessment logic, it exposes a generic video analysis and history-listing wrapper around another backend skill object. This kind of capability mismatch is dangerous because users and platform controls may grant permissions or trust based on the manifest, while the code can process arbitrary videos or enumerate prior analysis data under a misleading label.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file exposes generic CRUD wrappers and arbitrary HTTP methods that can be pointed at caller-supplied URLs, which is far broader than a pet body health analysis skill needs. In an agent environment, such reusable network primitives can be abused by higher-level code to access or modify remote resources unrelated to the declared purpose, increasing the risk of unauthorized actions or data exfiltration.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The add, edit, and delete methods provide remote resource modification capability without any visible authorization, scope checks, or business constraints tying them to pet health analysis. Because the skill's declared purpose is image/health assessment rather than remote administration, these write/delete primitives materially expand what the skill can do if invoked by other components.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This pet body health skill includes shared DAO code that persists and mutates user-account records, including lookup and update behavior unrelated to pet image/body analysis. That is dangerous because it expands the skill's authority beyond its stated purpose, enabling unnecessary handling of identity data and creating cross-feature data access risk if the skill is invoked in a broader agent environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The User model stores identity fields and authentication-related values such as token and open_token even though the declared skill purpose is pet health analysis. In this context, collecting and persisting tokens is especially risky because compromise of the local database or misuse of the DAO could expose credentials and enable account takeover or unauthorized API access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code resolves, creates, and persists platform user identities locally, including generating default open IDs and storing/reusing them across sessions. For a pet body-health analysis skill, this is unjustified persistence of identity state and can silently bind a user to backend services or create long-lived identifiers without informed consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This utility file performs broad authenticated backend access, token handling, user lookup, implicit account creation, and request enrichment that are unrelated to a pet body-health analysis skill. In this skill context, the hidden identity management and platform API access greatly expand the attack surface and can cause unauthorized data transmission, account creation, and cross-service interaction without clear user consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The helper auto-registers or logs in a user against a remote health backend via phoneLogin using locally derived identifiers. That behavior is unrelated to analyzing pet body condition and can create external accounts and transmit identifiers to third parties without the user's awareness, making the skill materially more dangerous in context.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool scope or permission boundaries despite directing execution of local Python scripts, handling files, using shell commands, and making network requests. In an agent ecosystem, this over-broad implicit capability increases the chance of unintended file access, arbitrary command execution paths, or exfiltration through networked script behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest advertises pet health analysis, but the documentation also includes cloud history-report querying and report-link retrieval. This discrepancy can cause orchestrators to approve the skill under a narrower trust model than its actual data-access behavior warrants.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The default activation rule is broad and ambiguous, allowing the skill to trigger whenever a pet image or URL is provided for analysis. Over-triggering can route user content into this skill unexpectedly, leading to unnecessary file handling, uploads, or backend processing under a looser consent boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases for history-report queries are broad enough to activate on ordinary conversation, which could cause unintended cloud queries and disclosure of report metadata. In a skill with internal identity linkage, accidental invocation increases the risk of exposing another user's or the current user's historical records without clear intent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatic internal identity handling and fallback local user creation are not necessary for basic pet media analysis and silently introduce account linkage and persistence. Hidden identity creation is dangerous because it can associate user content with backend records without meaningful transparency or consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The privacy section claims no plaintext personally identifiable information is stored, but elsewhere the skill references usernames or phone numbers as identity parameters. Inconsistent privacy claims are dangerous because they may mislead users and reviewers about actual collection, storage, and linkage of personal data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill exposes a history/listing operation for prior pet health analyses, which is outside the stated purpose of analyzing user-supplied media. Even if it only accesses the current user's records, this expands data access and retention surface and can reveal sensitive historical health-related content or metadata without clear necessity or consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code initializes and uses an internal identity primitive (open_id) despite the skill's advertised purpose being simple pet media analysis. Introducing hidden identity resolution increases the risk of unnecessary user tracking, cross-session linkage, or unauthorized access to user-scoped backend operations such as history retrieval.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2