Back to skill

Security audit

Plant Leaf Disease Identification | 植物叶片病害特征识别

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to perform cloud-based plant media analysis, but it also silently creates or reuses identity state, stores tokens locally, and exposes broader video/history/account behavior than a simple leaf-disease classifier implies.

Review this carefully before installing. It is not just a local plant-image classifier: it can upload media or URLs to a remote service, create or reuse an internal user identity, store authentication tokens in a local SQLite database, and query cloud report history. Install only if you are comfortable with that account linkage and remote processing model, and avoid using private images, private video, or internal URLs unless the publisher’s data handling is acceptable to you.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (62)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authentication/token handling, open-id persistence, directory discovery, filesystem access, and remote account registration/login are highly sensitive capabilities that do not belong in a narrowly described plant-analysis skill. This is especially dangerous because users may provide media believing they are using a simple classifier while the skill also manages identities and remote accounts behind the scenes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authentication/token handling, open-id persistence, directory discovery, filesystem access, and remote account registration/login are highly sensitive capabilities that do not belong in a narrowly described plant-analysis skill. This is especially dangerous because users may provide media believing they are using a simple classifier while the skill also manages identities and remote accounts behind the scenes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authentication/token handling, open-id persistence, directory discovery, filesystem access, and remote account registration/login are highly sensitive capabilities that do not belong in a narrowly described plant-analysis skill. This is especially dangerous because users may provide media believing they are using a simple classifier while the skill also manages identities and remote accounts behind the scenes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authentication/token handling, open-id persistence, directory discovery, filesystem access, and remote account registration/login are highly sensitive capabilities that do not belong in a narrowly described plant-analysis skill. This is especially dangerous because users may provide media believing they are using a simple classifier while the skill also manages identities and remote accounts behind the scenes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authentication/token handling, open-id persistence, directory discovery, filesystem access, and remote account registration/login are highly sensitive capabilities that do not belong in a narrowly described plant-analysis skill. This is especially dangerous because users may provide media believing they are using a simple classifier while the skill also manages identities and remote accounts behind the scenes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication/token handling, open-id persistence, directory discovery, filesystem access, and remote account registration/login are highly sensitive capabilities that do not belong in a narrowly described plant-analysis skill. This is especially dangerous because users may provide media believing they are using a simple classifier while the skill also manages identities and remote accounts behind the scenes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication/token handling, open-id persistence, directory discovery, filesystem access, and remote account registration/login are highly sensitive capabilities that do not belong in a narrowly described plant-analysis skill. This is especially dangerous because users may provide media believing they are using a simple classifier while the skill also manages identities and remote accounts behind the scenes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication/token handling, open-id persistence, directory discovery, filesystem access, and remote account registration/login are highly sensitive capabilities that do not belong in a narrowly described plant-analysis skill. This is especially dangerous because users may provide media believing they are using a simple classifier while the skill also manages identities and remote accounts behind the scenes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication/token handling, open-id persistence, directory discovery, filesystem access, and remote account registration/login are highly sensitive capabilities that do not belong in a narrowly described plant-analysis skill. This is especially dangerous because users may provide media believing they are using a simple classifier while the skill also manages identities and remote accounts behind the scenes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication/token handling, open-id persistence, directory discovery, filesystem access, and remote account registration/login are highly sensitive capabilities that do not belong in a narrowly described plant-analysis skill. This is especially dangerous because users may provide media believing they are using a simple classifier while the skill also manages identities and remote accounts behind the scenes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication/token handling, open-id persistence, directory discovery, filesystem access, and remote account registration/login are highly sensitive capabilities that do not belong in a narrowly described plant-analysis skill. This is especially dangerous because users may provide media believing they are using a simple classifier while the skill also manages identities and remote accounts behind the scenes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication/token handling, open-id persistence, directory discovery, filesystem access, and remote account registration/login are highly sensitive capabilities that do not belong in a narrowly described plant-analysis skill. This is especially dangerous because users may provide media believing they are using a simple classifier while the skill also manages identities and remote accounts behind the scenes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication/token handling, open-id persistence, directory discovery, filesystem access, and remote account registration/login are highly sensitive capabilities that do not belong in a narrowly described plant-analysis skill. This is especially dangerous because users may provide media believing they are using a simple classifier while the skill also manages identities and remote accounts behind the scenes.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-plant-leaf-disease-identification-analysis"
description: "AI-powered plant leaf disease identification from high-resolution leaf images. Detects disease lesion features (color, shape, distribution, surface deposits) such as white powdery patches (powdery mildew), rust-colored spore pustules (rust), brown necrotic spots (leaf spot), and outputs the most likely disease type with confidence score. Helps users quickly diagnose plant diseases and take timely measures. Scenarios: plant factories, greenhouses, home gardening, farm inspection. | 通过拍摄植物叶片的高清图像,利用AI视觉分析技术识别叶片上的病斑特征�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a skill that analyzes high-resolution plant leaf images and returns likely disease type with confidence. In code, the input handling and user-facing text repeatedly refer to videos and generic analysis reports: it accepts a 'network video URL'/'local video path', sends a 'videoUrl' parameter, and exposes generic report-list/report-export functions instead of a plant-disease-specific diagnosis flow. This is a strong semantic mismatch between the declared purpose and the implemented behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The implementation behavior materially conflicts with the declared skill purpose: it accepts MP4 video paths/URLs, invokes video-analysis routines, and exposes video-history listing rather than plant leaf image disease identification. This can misroute user data to unintended processing, create unauthorized handling of video content, and violate user trust or platform policy because operators and users would reasonably expect leaf-image diagnosis only.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This module provides broad local database CRUD and account-management capability unrelated to plant leaf disease image analysis. In the stated skill context, unnecessary user persistence expands the attack surface, enables unauthorized retention of personal data, and creates hidden state that can be abused by other components or agents.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The User model stores identity and credential-like fields including email, token, and open_token, which are unjustified for a leaf disease identification skill. Storing such secrets locally increases the risk of credential disclosure, cross-skill tracking, and misuse of accounts if the SQLite database is accessed by other code in the workspace.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code automatically resolves, reads, and if necessary creates persistent user identity state via local files and a database, despite the skill being presented as an image-based plant disease detector. This hidden identity lifecycle can deanonymize users, enable cross-session tracking, and prepare credentials for later outbound requests without clear necessity or consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This utility code performs remote account provisioning, token management, and authenticated API access that is unrelated to the stated purpose of plant leaf disease image analysis. The mismatch in declared functionality versus actual behavior greatly increases supply-chain risk because installing the skill can silently create identities, persist credentials, and transmit user-linked data to remote services.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code sends identity-related fields such as openId/mobile to a remote endpoint to silently log in or register a user, without any visible disclosure or confirmation. In the context of a plant disease analysis skill, this is especially concerning because users would not reasonably expect remote identity enrollment as part of image diagnosis.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares no explicit tool scope even though the manifest instructs use of shell, filesystem, environment, and network-capable code paths. That creates an over-privileged and weakly governed execution surface where callers and reviewers cannot easily constrain what the skill may access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The description is presented bilingually in Chinese and English, but the skill does not state that the user may choose their preferred response language or locale. For language-policy compliance, skills should explicitly offer or preserve user language preference rather than implicitly imposing a fixed bilingual format.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The default trigger condition is broad enough that the skill may auto-activate on generic plant-image requests without clear user intent. Over-broad triggering is risky because it can cause unintended file handling, network calls, or report lookups in contexts where the user did not explicitly request this skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code accepts both local/remote URLs and treats them as valid inputs, while the manifest describes only high-resolution leaf images. Accepting arbitrary URLs broadens the attack surface because downstream processing may fetch attacker-controlled resources, potentially enabling SSRF, internal network access, or ingestion of unsupported content; video acceptance also materially differs from the declared scope.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2