Back to skill

Security audit

Pet Oral Snapshot & Gum Redness Recognition | 宠物口腔抓拍与牙龈红肿识别

Security checks for vulnerabilities and agentic risk

Overview

This skill performs cloud-based pet oral-media analysis, but it also silently creates or reuses an account, stores tokens, uploads media, and can retrieve cloud report history, so it needs Review before installation.

Install only if you are comfortable with pet media and report history being sent to lifeemergence.com services, with the skill silently creating or reusing an account identity and storing API tokens in the workspace data directory. Use a test workspace or dedicated account if possible, and avoid supplying private household media or internal/private URLs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (54)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Automatic identity creation/reuse, local token/file handling, remote login, and injection of authentication headers into requests are highly sensitive behaviors not suggested by the user-facing description. In this context, the mismatch is more dangerous because the skill handles uploaded media and historical reports, so hidden account-linkage and token persistence can silently expand access to user data and remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Automatic identity creation/reuse, local token/file handling, remote login, and injection of authentication headers into requests are highly sensitive behaviors not suggested by the user-facing description. In this context, the mismatch is more dangerous because the skill handles uploaded media and historical reports, so hidden account-linkage and token persistence can silently expand access to user data and remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Automatic identity creation/reuse, local token/file handling, remote login, and injection of authentication headers into requests are highly sensitive behaviors not suggested by the user-facing description. In this context, the mismatch is more dangerous because the skill handles uploaded media and historical reports, so hidden account-linkage and token persistence can silently expand access to user data and remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Automatic identity creation/reuse, local token/file handling, remote login, and injection of authentication headers into requests are highly sensitive behaviors not suggested by the user-facing description. In this context, the mismatch is more dangerous because the skill handles uploaded media and historical reports, so hidden account-linkage and token persistence can silently expand access to user data and remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Automatic identity creation/reuse, local token/file handling, remote login, and injection of authentication headers into requests are highly sensitive behaviors not suggested by the user-facing description. In this context, the mismatch is more dangerous because the skill handles uploaded media and historical reports, so hidden account-linkage and token persistence can silently expand access to user data and remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Automatic identity creation/reuse, local token/file handling, remote login, and injection of authentication headers into requests are highly sensitive behaviors not suggested by the user-facing description. In this context, the mismatch is more dangerous because the skill handles uploaded media and historical reports, so hidden account-linkage and token persistence can silently expand access to user data and remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Automatic identity creation/reuse, local token/file handling, remote login, and injection of authentication headers into requests are highly sensitive behaviors not suggested by the user-facing description. In this context, the mismatch is more dangerous because the skill handles uploaded media and historical reports, so hidden account-linkage and token persistence can silently expand access to user data and remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Automatic identity creation/reuse, local token/file handling, remote login, and injection of authentication headers into requests are highly sensitive behaviors not suggested by the user-facing description. In this context, the mismatch is more dangerous because the skill handles uploaded media and historical reports, so hidden account-linkage and token persistence can silently expand access to user data and remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Automatic identity creation/reuse, local token/file handling, remote login, and injection of authentication headers into requests are highly sensitive behaviors not suggested by the user-facing description. In this context, the mismatch is more dangerous because the skill handles uploaded media and historical reports, so hidden account-linkage and token persistence can silently expand access to user data and remote services.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The YARA hit suggests suspicious metadata/manfiest characteristics consistent with tool or metadata poisoning. While the evidence here is weaker than the concrete scope mismatches, in combination with the unusually broad hidden behaviors it raises concern that the manifest may be crafted to influence trust or routing under an innocuous description.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-pet-oral-snapshot-gum-redness-analysis"
description: "Triggers when a user provides an oral snapshot image/video of a pet (usually auto-captured during yawning, lip-licking or mouth-opening moments) for analysis; supports local uploads or network URLs to call server-side APIs for oral health recognition, evaluating gum color (pink / bright red / dark red) and tartar coverage area, outputting standardized oral health observations to help early discovery of periodontal disease (without diagnosing diseases). Application scenarios: pet cameras, smart pet products, pet health management platforms. | 当用户提供宠物口腔抓拍图�

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares no explicit tool scope even though the documentation indicates capabilities involving shell execution, filesystem access, network access, environment use, and local file writes. In an agent setting, missing least-privilege boundaries makes it easier for the skill to invoke unnecessary high-risk capabilities or for downstream prompt/tool misuse to expand its effective access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Overly broad trigger conditions increase the chance the skill activates on loosely related conversation or generic keywords, causing unintended file handling, API calls, or historical-report access. In an automated agent environment, ambiguous triggering can become a security issue when a sensitive skill runs without clear user intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation expands the skill from media analysis into cloud history querying and report-link retrieval, which broadens the accessible data surface from current user input to previously stored records. That is security-relevant because it changes the trust model from one-shot analysis to account-linked data retrieval, potentially exposing historical sensitive content or metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that it will automatically save local files and call server-side APIs, but it does not clearly warn users about retention, transmission, or privacy implications. Because the data may include user-supplied media and account-linked reports, lack of notice can lead to unexpected disclosure of content to remote systems and local storage.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Automatic fallback to a local default user and silent account creation are dangerous because they can cause cross-user data mixing, hidden persistence, and unintended association of reports with a synthetic or reused identity. In a health-adjacent reporting workflow, that can expose another user's history or create records under an identity the user never knowingly authorized.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script exposes a hidden listing mode via --list that retrieves analysis history for the current/internal user, even though the declared skill purpose is only oral snapshot analysis. Hidden user-scoped functionality increases the attack surface and can expose prior health-analysis records or metadata without clear user awareness, making this an information disclosure and capability creep issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code presents the tool description, argument help, progress message, and error text only in Chinese. That imposes a fixed language on all users without opt-in or any visible localization mechanism, which fits the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code resolves an internal current open_id for all executions, then uses it for hidden user-scoped operations such as listing analysis history. This is risky because identity binding is occurring behind the scenes for a feature unrelated to simple image/video analysis, which can enable unintended access to another user's records if identity resolution is weak, ambient, or spoofable.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file returns user-visible messages such as 分析报告结构化结果, 获取报告导出图片链接, and other Chinese-only status/error text. That is a natural-language policy concern because the skill fixes the interaction language without offering the user a language choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest says the skill analyzes pet oral snapshot images or videos, including local uploads and network URLs. In code, remote inputs are always sent as "videoUrl", and the user-facing validation message requires a local video path or network video URL, with no corresponding image-URL handling shown here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill reads arbitrary local file contents and uploads them, or forwards user-supplied remote URLs to a backend analysis service, without any visible consent, destination disclosure, or URL safety controls in this code. In a pet-camera or health context, this can expose sensitive media and can also enable the backend to fetch attacker-controlled URLs, increasing privacy and SSRF-related risk depending on server-side protections.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest narrowly claims analysis of pet oral snapshots/videos for gum color and tartar coverage, but this file exposes generic 'video analysis' and history listing flows without any oral-domain validation, oral-health parameters, or result shaping. The actual behavior appears to delegate arbitrary input to a backend video-analysis capability rather than enforcing the manifest's stated oral-health scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code accepts a local path or remote URL and forwards it to an external analysis service via skill.get_output_analysis without providing a clear user-facing disclosure that user-supplied media or references may leave the local environment. In a pet-health context, uploaded oral images/videos may contain sensitive household, owner, location, or device-captured information, so silent transmission creates a meaningful privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2