Back to skill

Security audit

Reptile Excrement Analysis (Urate / Feces) | 爬宠排泄物形态识别(尿酸/粪便)

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a remote reptile waste image-analysis client, but it silently creates or reuses user identities, stores tokens locally, and sends media or URLs to an external service.

Install only if you are comfortable sending reptile enclosure images or URLs to the configured Life Emergence cloud service and having the skill silently create or reuse an account-linked local identity. Review or clear the workspace data directory and smyx-api-key.txt if you do not want persisted identifiers or tokens reused across runs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (54)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The most concerning mismatch is the combination of external API communication, authentication/token handling, automatic user registration/login, local filesystem access, API-key file reads, and local identity persistence, none of which are implied by the declared image-analysis function. In context, this means a pet-health skill can silently collect media, bind it to identities, persist user state locally, and communicate with external services—far more dangerous than its description suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The most concerning mismatch is the combination of external API communication, authentication/token handling, automatic user registration/login, local filesystem access, API-key file reads, and local identity persistence, none of which are implied by the declared image-analysis function. In context, this means a pet-health skill can silently collect media, bind it to identities, persist user state locally, and communicate with external services—far more dangerous than its description suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The most concerning mismatch is the combination of external API communication, authentication/token handling, automatic user registration/login, local filesystem access, API-key file reads, and local identity persistence, none of which are implied by the declared image-analysis function. In context, this means a pet-health skill can silently collect media, bind it to identities, persist user state locally, and communicate with external services—far more dangerous than its description suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The most concerning mismatch is the combination of external API communication, authentication/token handling, automatic user registration/login, local filesystem access, API-key file reads, and local identity persistence, none of which are implied by the declared image-analysis function. In context, this means a pet-health skill can silently collect media, bind it to identities, persist user state locally, and communicate with external services—far more dangerous than its description suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The most concerning mismatch is the combination of external API communication, authentication/token handling, automatic user registration/login, local filesystem access, API-key file reads, and local identity persistence, none of which are implied by the declared image-analysis function. In context, this means a pet-health skill can silently collect media, bind it to identities, persist user state locally, and communicate with external services—far more dangerous than its description suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The most concerning mismatch is the combination of external API communication, authentication/token handling, automatic user registration/login, local filesystem access, API-key file reads, and local identity persistence, none of which are implied by the declared image-analysis function. In context, this means a pet-health skill can silently collect media, bind it to identities, persist user state locally, and communicate with external services—far more dangerous than its description suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The most concerning mismatch is the combination of external API communication, authentication/token handling, automatic user registration/login, local filesystem access, API-key file reads, and local identity persistence, none of which are implied by the declared image-analysis function. In context, this means a pet-health skill can silently collect media, bind it to identities, persist user state locally, and communicate with external services—far more dangerous than its description suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The most concerning mismatch is the combination of external API communication, authentication/token handling, automatic user registration/login, local filesystem access, API-key file reads, and local identity persistence, none of which are implied by the declared image-analysis function. In context, this means a pet-health skill can silently collect media, bind it to identities, persist user state locally, and communicate with external services—far more dangerous than its description suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The most concerning mismatch is the combination of external API communication, authentication/token handling, automatic user registration/login, local filesystem access, API-key file reads, and local identity persistence, none of which are implied by the declared image-analysis function. In context, this means a pet-health skill can silently collect media, bind it to identities, persist user state locally, and communicate with external services—far more dangerous than its description suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The most concerning mismatch is the combination of external API communication, authentication/token handling, automatic user registration/login, local filesystem access, API-key file reads, and local identity persistence, none of which are implied by the declared image-analysis function. In context, this means a pet-health skill can silently collect media, bind it to identities, persist user state locally, and communicate with external services—far more dangerous than its description suggests.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
86% confidence
Finding

The YARA hit for MCP/tool metadata poisoning indicators in the manifest is a strong red flag because metadata is what routing and trust decisions often rely on. Even if partially triggered by obfuscated or malformed description text, suspicious manifest content can be used to manipulate tool selection, conceal real capabilities, or evade review, which is especially dangerous alongside the extensive description-behavior mismatches.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-reptile-excrement-analysis-analysis"
description: "Through a fixed camera in the reptile enclosure, the system captures a high-definition image (or a static video frame) once excrement is found, and uses AI visual analysis to identify urate (white/milky-white crystals or paste, common in lizards, geckos, etc.) — including its size (pixel area) — and to identify the morphology of feces (normally formed log, soft pasty, watery, or bloody). | 通过爬宠箱固定摄像头,在发现排泄物后拍摄高清图像(或分析视频中的静态帧),利用 AI 视觉分析技术识别尿酸(白色/乳白色结晶或膏状物�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes capturing a fixed-camera image or static frame when excrement is found and analyzing urate size and feces morphology. In code, the exposed operations are generic analyze_video and show_analyze_list, with CLI text and parameters centered on arbitrary video input or URL-based video analysis, and no code handling excrement detection, still-image capture, urate measurement, or feces morphology classification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code generates, resolves, and persists default user identities for the current agent, including creating local user records when no explicit identity is supplied. That is dangerous because it silently establishes durable identities and can enable later authenticated network activity without informed user approval, which is unrelated to the stated analysis-only skill purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The utility code performs network authentication, account lookup/provisioning, token handling, and authenticated API requests that are unrelated to reptile excrement image analysis. In this skill context, that broader capability materially increases risk because installing or invoking the skill can cause identity-linked outbound actions and persistence far beyond the user-visible purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool/permission scope while its documented behavior includes shell execution, local file save/read/write, environment use, and network access. In an agent setting, missing least-privilege boundaries can let a seemingly narrow image-analysis skill invoke broader capabilities than users expect, increasing the blast radius of prompt injection or misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill name, role instructions, workflow, and operational guidance are predominantly written in Chinese, and there is no explicit statement that the user may choose their preferred language for interaction or output. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states that uploaded attachments are automatically saved locally, but it does not present a clear user warning about this storage behavior near the data-collection flow. For image/video media from homes or facilities, silent local persistence increases privacy, retention, and secondary-access risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill accepts remote image/video URLs and notes that the API service will automatically download them, but it does not clearly warn users that submitted URLs are forwarded to an external service for retrieval and analysis. This creates privacy and security concerns, including unexpected third-party access and possible SSRF-like behavior if URL handling is not tightly constrained.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The surrounding documentation and help text are explicitly about reptile excrement analysis. However, the selectable pet types are cat, dog, and other, which contradicts the reptile-focused intent and suggests reused logic from a different animal-analysis context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code initializes an internal user identity and then uses that identity for record-listing behavior without clear user disclosure or necessity for the stated visual-analysis task. Hidden identity binding increases the risk of cross-user data exposure, silent tracking, or unintended access to historical records if identity resolution is incorrect or manipulated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script performs hidden internal identity initialization without presenting that behavior in help output or normal user disclosure. In the context of a simple image-analysis skill, undisclosed identity handling is more dangerous because users would not reasonably expect tracking or account-scoped data access, increasing privacy and trust risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes identifying urate size and feces morphology from enclosure images. The runtime message says the tool also compares results against species-normal ranges and evaluates kidney and intestinal health, which is a broader diagnostic/assessment function not stated in the manifest.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

SQP-3 applies to natural-language policy issues in any file type. Multiple returned UI strings are fixed in Chinese, such as the report header and export-link text, with no indication of locale selection or user opt-in, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2