Back to skill

Security audit

Reptile Tail Loss (Autotomy) Detection | 守宫/蜥蜴尾巴断尾识别

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its reptile tail-analysis purpose, but it silently creates or reuses a cloud-linked identity and stores service tokens locally, so it should be reviewed before installation.

Install only if you are comfortable sending reptile images, videos, URLs, and linked report-history requests to the lifeemergence cloud service. Review how the workspace data directory is protected, because this skill can create a local database and store service tokens there. Prefer an explicit consent step for cloud history lookup and account creation before using it with sensitive media.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (58)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The combination of remote authenticated API communication, automatic open-id generation/account provisioning, local workspace reads/writes, and hidden identity linkage is substantially broader than the stated animal-image analysis function. This is dangerous because it couples sensitive media processing with persistent identity and storage operations that users are instructed not to see or control.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The combination of remote authenticated API communication, automatic open-id generation/account provisioning, local workspace reads/writes, and hidden identity linkage is substantially broader than the stated animal-image analysis function. This is dangerous because it couples sensitive media processing with persistent identity and storage operations that users are instructed not to see or control.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The combination of remote authenticated API communication, automatic open-id generation/account provisioning, local workspace reads/writes, and hidden identity linkage is substantially broader than the stated animal-image analysis function. This is dangerous because it couples sensitive media processing with persistent identity and storage operations that users are instructed not to see or control.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The combination of remote authenticated API communication, automatic open-id generation/account provisioning, local workspace reads/writes, and hidden identity linkage is substantially broader than the stated animal-image analysis function. This is dangerous because it couples sensitive media processing with persistent identity and storage operations that users are instructed not to see or control.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of remote authenticated API communication, automatic open-id generation/account provisioning, local workspace reads/writes, and hidden identity linkage is substantially broader than the stated animal-image analysis function. This is dangerous because it couples sensitive media processing with persistent identity and storage operations that users are instructed not to see or control.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of remote authenticated API communication, automatic open-id generation/account provisioning, local workspace reads/writes, and hidden identity linkage is substantially broader than the stated animal-image analysis function. This is dangerous because it couples sensitive media processing with persistent identity and storage operations that users are instructed not to see or control.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of remote authenticated API communication, automatic open-id generation/account provisioning, local workspace reads/writes, and hidden identity linkage is substantially broader than the stated animal-image analysis function. This is dangerous because it couples sensitive media processing with persistent identity and storage operations that users are instructed not to see or control.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of remote authenticated API communication, automatic open-id generation/account provisioning, local workspace reads/writes, and hidden identity linkage is substantially broader than the stated animal-image analysis function. This is dangerous because it couples sensitive media processing with persistent identity and storage operations that users are instructed not to see or control.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of remote authenticated API communication, automatic open-id generation/account provisioning, local workspace reads/writes, and hidden identity linkage is substantially broader than the stated animal-image analysis function. This is dangerous because it couples sensitive media processing with persistent identity and storage operations that users are instructed not to see or control.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of remote authenticated API communication, automatic open-id generation/account provisioning, local workspace reads/writes, and hidden identity linkage is substantially broader than the stated animal-image analysis function. This is dangerous because it couples sensitive media processing with persistent identity and storage operations that users are instructed not to see or control.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of remote authenticated API communication, automatic open-id generation/account provisioning, local workspace reads/writes, and hidden identity linkage is substantially broader than the stated animal-image analysis function. This is dangerous because it couples sensitive media processing with persistent identity and storage operations that users are instructed not to see or control.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

A metadata-poisoning indicator in the manifest is suspicious because tool/skill metadata is a high-trust channel that can influence routing, tool selection, and reviewer assumptions. Even if the embedded characters are subtle, anomalous or obfuscated metadata in a skill already showing scope mismatches raises the risk of deceptive packaging or parser confusion.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-reptile-tail-loss-detection-analysis"
description: "Through fixed enclosure cameras, the system periodically captures tail images of geckos and lizards and uses AI visual analysis to detect tail length (compared with historical images or body-length reference values), tail-tip wounds, scabs, or abnormal shortening. | 通过爬宠箱固定摄像头,定期拍摄守宫、蜥蜴等爬行动物的尾部图像,利用 AI 视觉分析技术检测尾巴长度(与历史图像或同体长参考值对比)、尾部尖端伤口、结痂或异常短缩。当检测到尾巴长度突然明显缩短(例如缩短超过 20%)、尾部断�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation materially diverges from the declared purpose: instead of specialized reptile tail-image monitoring, it exposes a generic video analysis and history-listing interface. This kind of scope mismatch is dangerous because it can conceal broader data processing behavior than users or reviewers expect, weakening trust boundaries and enabling misuse of the skill for unrelated surveillance or content analysis.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This module defines a generic shared user-account DAO with identity fields and token storage that are unrelated to reptile tail-loss image analysis. In the context of a narrowly scoped animal-health skill, hidden cross-skill user persistence materially expands data collection and attack surface beyond user expectations, increasing the risk of unauthorized tracking, credential mishandling, and privilege boundary erosion.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The User model stores token and open_token fields even though the skill’s declared purpose is enclosure-camera tail injury detection. Storing authentication-like secrets in a local shared SQLite database without purpose limitation or protection increases the chance of credential leakage, replay, or unauthorized reuse across skills.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility implements identity selection, persistence, and automatic creation of default user identifiers, including reading an internal identity value from a local file and storing user records in a local database. That behavior is unrelated to reptile tail-loss image analysis and expands the skill into covert account-context management, increasing privacy and misuse risk if invoked without explicit user consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The HTTP wrapper does much more than issue application requests: it resolves user identity, loads and persists tokens, retries authorization, updates local user records, and injects user metadata into outbound requests. For a reptile-tail analysis skill, this broad remote account/token management is unnecessary and creates a hidden capability for external service coupling, user tracking, and unauthorized account actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code can silently register or log in a user against an external health-service endpoint using a generated or recovered identifier, then retrieve tokens. Auto-registering accounts on a third-party service is highly sensitive behavior and is not justified by the declared purpose of detecting reptile tail injuries from enclosure images.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares no explicit tool scope even though the documented behavior requires shell, network, file, and environment access. This creates excessive implicit privilege and makes it harder for a host system to enforce least privilege or detect abuse if the skill is repurposed or the backing scripts behave unexpectedly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation expands the skill from image analysis into cloud history retrieval and report-link delivery, broadening access to remote user-associated data beyond the manifest's core purpose. Scope expansion in documentation is dangerous because it can smuggle in extra data flows and permissions without clear review boundaries.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document claims not to provide medical advice while also directing the system to output care actions such as isolation and wound-cleaning guidance. Contradictory instructions are risky because they blur safety boundaries, can mislead users about the authority of the output, and may hide higher-liability behavior behind softer wording.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The default trigger is broad enough to auto-invoke on many reptile-tail image requests, which can cause unintended processing, file saving, or remote API submission without sufficiently specific user intent. In a skill that also performs identity-linked history access and external network calls, over-triggering increases privacy and misuse risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatically saving uploaded files locally without a clear user-facing data-handling notice creates avoidable privacy and retention risk. Media may contain sensitive context, and silent persistence expands exposure if the host or workspace is later accessed by other tools or users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs direct cloud API queries for history tied to internal identity without a prominent upfront warning that user-associated report data will be fetched remotely. Hidden remote retrieval of linked records is especially sensitive here because the skill also auto-handles identity and discourages exposing those identity values to the user.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file prohibits local-history use while simultaneously describing local default-user reuse and local file saving. This contradiction is dangerous because it obscures what state is persisted locally and undermines privacy assurances about where identity-linked report data comes from.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2