Back to skill

Security audit

Reptile Shedding Progress Analysis | 爬宠蜕皮进度识别

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with reptile image analysis, but it silently creates or reuses a cloud identity, sends media to a remote service, and stores access tokens locally without enough user control or retention detail.

Install only if you are comfortable with reptile images or videos and analysis history being sent to lifeemergence.com/open.lifeemergence.com, and with the skill creating or reusing a local cloud identity plus storing service tokens in the workspace data directory. Review retention and account controls before using it with sensitive media.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (63)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Outbound HTTP requests, automatic account creation/login, token persistence, workspace discovery, and file access are highly sensitive behaviors when omitted from the skill’s stated purpose. This combination can collect, store, and transmit user-linked data under the guise of a harmless enclosure-monitoring tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Outbound HTTP requests, automatic account creation/login, token persistence, workspace discovery, and file access are highly sensitive behaviors when omitted from the skill’s stated purpose. This combination can collect, store, and transmit user-linked data under the guise of a harmless enclosure-monitoring tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Outbound HTTP requests, automatic account creation/login, token persistence, workspace discovery, and file access are highly sensitive behaviors when omitted from the skill’s stated purpose. This combination can collect, store, and transmit user-linked data under the guise of a harmless enclosure-monitoring tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Outbound HTTP requests, automatic account creation/login, token persistence, workspace discovery, and file access are highly sensitive behaviors when omitted from the skill’s stated purpose. This combination can collect, store, and transmit user-linked data under the guise of a harmless enclosure-monitoring tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Outbound HTTP requests, automatic account creation/login, token persistence, workspace discovery, and file access are highly sensitive behaviors when omitted from the skill’s stated purpose. This combination can collect, store, and transmit user-linked data under the guise of a harmless enclosure-monitoring tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Outbound HTTP requests, automatic account creation/login, token persistence, workspace discovery, and file access are highly sensitive behaviors when omitted from the skill’s stated purpose. This combination can collect, store, and transmit user-linked data under the guise of a harmless enclosure-monitoring tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Outbound HTTP requests, automatic account creation/login, token persistence, workspace discovery, and file access are highly sensitive behaviors when omitted from the skill’s stated purpose. This combination can collect, store, and transmit user-linked data under the guise of a harmless enclosure-monitoring tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Outbound HTTP requests, automatic account creation/login, token persistence, workspace discovery, and file access are highly sensitive behaviors when omitted from the skill’s stated purpose. This combination can collect, store, and transmit user-linked data under the guise of a harmless enclosure-monitoring tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Outbound HTTP requests, automatic account creation/login, token persistence, workspace discovery, and file access are highly sensitive behaviors when omitted from the skill’s stated purpose. This combination can collect, store, and transmit user-linked data under the guise of a harmless enclosure-monitoring tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Outbound HTTP requests, automatic account creation/login, token persistence, workspace discovery, and file access are highly sensitive behaviors when omitted from the skill’s stated purpose. This combination can collect, store, and transmit user-linked data under the guise of a harmless enclosure-monitoring tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Outbound HTTP requests, automatic account creation/login, token persistence, workspace discovery, and file access are highly sensitive behaviors when omitted from the skill’s stated purpose. This combination can collect, store, and transmit user-linked data under the guise of a harmless enclosure-monitoring tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Outbound HTTP requests, automatic account creation/login, token persistence, workspace discovery, and file access are highly sensitive behaviors when omitted from the skill’s stated purpose. This combination can collect, store, and transmit user-linked data under the guise of a harmless enclosure-monitoring tool.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

A metadata-poisoning YARA hit in the manifest description is concerning in this ecosystem because skill metadata influences routing, trust, and tool selection. Even though the matched text here is not conclusive on its own, combined with the strong description/behavior mismatches it raises suspicion that metadata may be crafted to influence the agent’s interpretation while hiding broader capabilities.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-reptile-shedding-progress-analysis"
description: "Through a fixed camera in the reptile enclosure, the system periodically captures full-body high-definition images of reptiles (snakes, lizards, geckos) and uses AI visual analysis to detect changes in body colour (normal vivid → dull/whitish → restored vivid) and eye state (clear → opaque milky 'blue-phase' → clear again), to determine the shedding phase: preparation phase (skin turns whitish, eyes turn opaque), in-progress. | 通过爬宠箱固定摄像头,定期拍摄爬行动物(如蛇、蜥蜴、守宫)的全身高清图像,利用 AI 视觉分析技术检测�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill manifest describes a narrow fixed-camera reptile shedding image workflow, but the implementation accepts arbitrary local files and arbitrary remote HTTP/HTTPS URLs for generic analysis submission. This scope mismatch is dangerous because it enables use of the skill as a broader file/URL forwarding mechanism than users or reviewers would expect, increasing risks of unintended data exfiltration, policy bypass, and misuse of backend analysis capabilities.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation materially diverges from the declared purpose: instead of a fixed-camera reptile shedding image-analysis workflow, it exposes a generic video analysis/listing interface. Such scope mismatch is dangerous because users, reviewers, and platform controls may grant trust or permissions based on the manifest while the code performs broader operations than expected, including generic media processing and history retrieval. In this context, the mismatch increases risk because the skill claims a narrow husbandry use case but implements reusable analysis plumbing that could be repurposed for unrelated surveillance or data handling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The User model stores personal profile fields and especially token/open_token values, which are sensitive credentials. For a reptile shedding analyzer, collecting and persisting such data is unjustified; if compromised, it could lead to account takeover, privacy violations, or reuse of leaked tokens in other systems.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility module performs identity resolution, local user provisioning, token persistence, and automatic external login/account creation flows that are unrelated to reptile shedding analysis. In context, this is dangerous because using the skill can silently bind a local or generated identity, read stored identifiers, and transmit them to remote services, expanding data collection and account linkage far beyond the declared camera-analysis purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool scope even though it appears able to read/write files, access environment data, use the network, and invoke shell commands. Missing least-privilege boundaries is dangerous because the runtime may permit broader capabilities than users or reviewers expect, increasing the blast radius if the script is compromised or misused.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest frames the skill as visual shedding-phase analysis, but the documentation adds cloud historical-report querying and report-link retrieval. This scope expansion matters because it introduces additional remote data access paths and report exposure not obvious from the top-level description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Allowing arbitrary local files and network URLs expands the skill well beyond a fixed-camera periodic monitor. This broader ingestion surface increases risk from sensitive local file processing and untrusted remote resources, especially in a skill that already appears to interact with external services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file contains extensive operational instructions in Chinese and presents the role and behavior primarily in a fixed bilingual/Chinese-oriented format, but it does not explicitly state that the user may choose the response language. A skill that implicitly fixes language behavior without opt-in can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

An overly broad default trigger may cause the skill to run on generic reptile images rather than only shedding-related requests. In this context, over-triggering is dangerous because the skill appears to have undeclared network, file, and history-query capabilities, so unnecessary invocation increases data exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Broad natural-language triggers for history queries can cause unintended retrieval of cloud-stored reports. Because these reports appear tied to internal identity handling, accidental invocation could expose user-linked historical data or fetch remote content without clear intent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Automatic local-file saving of uploaded attachments creates undeclared persistence of user-provided media. That is risky because it can retain sensitive images/videos longer than expected, increase exposure to local file disclosure, and widen the impact of compromise on the host running the skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill's stated purpose is reptile shedding analysis, but the implementation also exposes a history-listing function tied to an internal user identity. This is a scope expansion into user-record access that is not disclosed by the manifest, increasing the risk of unauthorized access to prior analysis records or metadata.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2