Back to skill

Security audit

Reptile Circadian Activity Analysis | 爬宠活动量昼夜节律分析

Security checks for vulnerabilities and agentic risk

Overview

The skill is a cloud-backed reptile video analysis tool, but it silently creates or reuses an identity and stores service tokens locally, so users should review it before installing.

Install only if you are comfortable with reptile enclosure media and report history being processed by lifeemergence.com services and linked to an automatically managed local/remote identity. Review or clear the workspace data store if you do not want persisted service tokens or default user records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (62)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to perform HTTP requests, authentication/token management, user lookup/creation, and filesystem operations that are not part of the stated reptile-monitoring purpose. These undeclared control-plane capabilities substantially increase blast radius because compromise or misuse could affect user accounts, tokens, and locally stored data, not just analysis output.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to perform HTTP requests, authentication/token management, user lookup/creation, and filesystem operations that are not part of the stated reptile-monitoring purpose. These undeclared control-plane capabilities substantially increase blast radius because compromise or misuse could affect user accounts, tokens, and locally stored data, not just analysis output.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill appears to perform HTTP requests, authentication/token management, user lookup/creation, and filesystem operations that are not part of the stated reptile-monitoring purpose. These undeclared control-plane capabilities substantially increase blast radius because compromise or misuse could affect user accounts, tokens, and locally stored data, not just analysis output.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to perform HTTP requests, authentication/token management, user lookup/creation, and filesystem operations that are not part of the stated reptile-monitoring purpose. These undeclared control-plane capabilities substantially increase blast radius because compromise or misuse could affect user accounts, tokens, and locally stored data, not just analysis output.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to perform HTTP requests, authentication/token management, user lookup/creation, and filesystem operations that are not part of the stated reptile-monitoring purpose. These undeclared control-plane capabilities substantially increase blast radius because compromise or misuse could affect user accounts, tokens, and locally stored data, not just analysis output.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill appears to perform HTTP requests, authentication/token management, user lookup/creation, and filesystem operations that are not part of the stated reptile-monitoring purpose. These undeclared control-plane capabilities substantially increase blast radius because compromise or misuse could affect user accounts, tokens, and locally stored data, not just analysis output.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to perform HTTP requests, authentication/token management, user lookup/creation, and filesystem operations that are not part of the stated reptile-monitoring purpose. These undeclared control-plane capabilities substantially increase blast radius because compromise or misuse could affect user accounts, tokens, and locally stored data, not just analysis output.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to perform HTTP requests, authentication/token management, user lookup/creation, and filesystem operations that are not part of the stated reptile-monitoring purpose. These undeclared control-plane capabilities substantially increase blast radius because compromise or misuse could affect user accounts, tokens, and locally stored data, not just analysis output.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform HTTP requests, authentication/token management, user lookup/creation, and filesystem operations that are not part of the stated reptile-monitoring purpose. These undeclared control-plane capabilities substantially increase blast radius because compromise or misuse could affect user accounts, tokens, and locally stored data, not just analysis output.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform HTTP requests, authentication/token management, user lookup/creation, and filesystem operations that are not part of the stated reptile-monitoring purpose. These undeclared control-plane capabilities substantially increase blast radius because compromise or misuse could affect user accounts, tokens, and locally stored data, not just analysis output.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform HTTP requests, authentication/token management, user lookup/creation, and filesystem operations that are not part of the stated reptile-monitoring purpose. These undeclared control-plane capabilities substantially increase blast radius because compromise or misuse could affect user accounts, tokens, and locally stored data, not just analysis output.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform HTTP requests, authentication/token management, user lookup/creation, and filesystem operations that are not part of the stated reptile-monitoring purpose. These undeclared control-plane capabilities substantially increase blast radius because compromise or misuse could affect user accounts, tokens, and locally stored data, not just analysis output.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform HTTP requests, authentication/token management, user lookup/creation, and filesystem operations that are not part of the stated reptile-monitoring purpose. These undeclared control-plane capabilities substantially increase blast radius because compromise or misuse could affect user accounts, tokens, and locally stored data, not just analysis output.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform HTTP requests, authentication/token management, user lookup/creation, and filesystem operations that are not part of the stated reptile-monitoring purpose. These undeclared control-plane capabilities substantially increase blast radius because compromise or misuse could affect user accounts, tokens, and locally stored data, not just analysis output.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-reptile-circadian-activity-analysis"
description: "Through a fixed camera in a reptile enclosure, the system continuously captures 24-hour video and uses motion-detection techniques to count hourly activity volume (pixel-change area or motion-pixel ratio), producing a circadian activity distribution chart. | 通过爬宠箱固定摄像头,连续 24 小时采集视频,利用运动检测技术统计每小时的活动量(像素变化面积或运动像素比例),生成昼夜活动分布图。当节律异常持续多日时,输出'昼夜节律紊乱'提示,建议调整光照周期或检查环境干扰(如夜间灯光、

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill auto-resolves, reuses, or creates a default local user identity even though this is not justified by the stated analysis purpose. Silent identity creation/persistence is dangerous because it can bind reports and uploads to hidden accounts, enable unintended cross-session access, and create unconsented personal-data retention.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file exposes generic wrappers for arbitrary HTTP GET/POST/PUT/DELETE plus broad CRUD operations that are not constrained to the stated reptile circadian-analysis purpose. In an agent skill context, such reusable remote-access primitives can be invoked to reach unrelated backend endpoints, expanding the attack surface for unauthorized data access, modification, or exfiltration if higher-level controls are weak or bypassed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The presence of add/edit/delete and arbitrary remote modification methods gives the skill the ability to change or remove remote resources despite its declared read/analysis-oriented purpose. That mismatch is dangerous because it enables destructive or unauthorized state changes if the skill is exposed to untrusted inputs, misconfigured permissions, or reuse by other components.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file defines generic user-account persistence, lookup, and mutation logic, including default-user selection, which is materially broader than the stated reptile circadian video-analysis purpose. Scope expansion like this increases attack surface and creates unnecessary handling of identity-related data in a skill that should primarily process enclosure video activity metrics.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The User model stores token and open_token fields even though the skill description is limited to reptile activity analysis from enclosure video. Retaining authentication material unrelated to the stated function creates unnecessary credential exposure risk through local database compromise, logging, backups, or unintended cross-skill access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This utility layer auto-resolves identities, logs in or auto-registers remote accounts, and persists tokens locally, which is unrelated to reptile circadian video analysis. In the context of a camera-analysis skill, hidden account provisioning and credential storage materially expand the trust boundary and enable covert linkage of the user's workspace and identity to external services.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises and documents capabilities that imply shell, filesystem, environment, and network access, but it does not declare any explicit tool scope or permissions boundaries. This increases the chance of over-privileged execution because reviewers and runtime policy engines cannot easily constrain what the skill is allowed to access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest frames the skill as local motion analysis, while the body adds cloud processing, historical report querying, and remote report links. This inconsistency is dangerous because it obscures external data transfer and makes privacy review incomplete.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The default trigger is broad enough that the skill may activate on generic reptile-video requests without the user specifically requesting this workflow. Over-broad auto-triggering is risky because it can unexpectedly save files locally or send media to remote services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Automatic cloud history-query behavior is unrelated to the narrow analytic purpose and can expose previously stored reports without sufficiently explicit user intent. Because the feature is triggered by broad phrases, ordinary conversation may unintentionally retrieve account-scoped data.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2