Back to skill

Security audit

Fish Flashing & Scraping Detection (Ectoparasite Warning) | 爬宠体温调节行为识别(晒点/躲避)

Security checks for vulnerabilities and agentic risk

Overview

This skill performs the advertised reptile video analysis, but it silently creates or reuses a local cloud identity and stores account tokens/history context.

Review before installing. Use it only if you are comfortable sending reptile enclosure media or URLs to the configured LifeEmergence cloud service and allowing the skill to create/reuse a local identity database with stored tokens. Avoid use in shared workspaces unless account association and history access are clearly controlled.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential-like data, creating or resolving user identities, persisting them locally, and making authenticated outbound requests is a substantial capability escalation beyond reptile media analysis. In this context, the skill can handle credentials and user-linked cloud data without clear disclosure, creating risks of unauthorized access, data exfiltration, and account abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential-like data, creating or resolving user identities, persisting them locally, and making authenticated outbound requests is a substantial capability escalation beyond reptile media analysis. In this context, the skill can handle credentials and user-linked cloud data without clear disclosure, creating risks of unauthorized access, data exfiltration, and account abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential-like data, creating or resolving user identities, persisting them locally, and making authenticated outbound requests is a substantial capability escalation beyond reptile media analysis. In this context, the skill can handle credentials and user-linked cloud data without clear disclosure, creating risks of unauthorized access, data exfiltration, and account abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential-like data, creating or resolving user identities, persisting them locally, and making authenticated outbound requests is a substantial capability escalation beyond reptile media analysis. In this context, the skill can handle credentials and user-linked cloud data without clear disclosure, creating risks of unauthorized access, data exfiltration, and account abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential-like data, creating or resolving user identities, persisting them locally, and making authenticated outbound requests is a substantial capability escalation beyond reptile media analysis. In this context, the skill can handle credentials and user-linked cloud data without clear disclosure, creating risks of unauthorized access, data exfiltration, and account abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential-like data, creating or resolving user identities, persisting them locally, and making authenticated outbound requests is a substantial capability escalation beyond reptile media analysis. In this context, the skill can handle credentials and user-linked cloud data without clear disclosure, creating risks of unauthorized access, data exfiltration, and account abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential-like data, creating or resolving user identities, persisting them locally, and making authenticated outbound requests is a substantial capability escalation beyond reptile media analysis. In this context, the skill can handle credentials and user-linked cloud data without clear disclosure, creating risks of unauthorized access, data exfiltration, and account abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential-like data, creating or resolving user identities, persisting them locally, and making authenticated outbound requests is a substantial capability escalation beyond reptile media analysis. In this context, the skill can handle credentials and user-linked cloud data without clear disclosure, creating risks of unauthorized access, data exfiltration, and account abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential-like data, creating or resolving user identities, persisting them locally, and making authenticated outbound requests is a substantial capability escalation beyond reptile media analysis. In this context, the skill can handle credentials and user-linked cloud data without clear disclosure, creating risks of unauthorized access, data exfiltration, and account abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential-like data, creating or resolving user identities, persisting them locally, and making authenticated outbound requests is a substantial capability escalation beyond reptile media analysis. In this context, the skill can handle credentials and user-linked cloud data without clear disclosure, creating risks of unauthorized access, data exfiltration, and account abuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading local credential-like data, creating or resolving user identities, persisting them locally, and making authenticated outbound requests is a substantial capability escalation beyond reptile media analysis. In this context, the skill can handle credentials and user-linked cloud data without clear disclosure, creating risks of unauthorized access, data exfiltration, and account abuse.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-reptile-thermoregulation-behavior-analysis"
description: "Through fixed enclosure cameras, the system analyzes behavior videos of reptiles (lizards, snakes, turtles) and detects movement frequency and dwell duration between the basking zone (heated area under the basking lamp) and the hiding zone (cave/cool side). | 通过爬宠箱固定摄像头,分析爬行动物(如蜥蜴、蛇、龟)的行为视频,检测宠物在晒点(加热灯下方高温区域)与躲避区(洞穴、冷区)之间的移动频次、停留时长以及活动节律。系统连续监测,生成每日温区利用报告,异常时推送提醒。"
versio

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill omits a clear warning that uploaded media and report queries may be transmitted to cloud services. For a video-analysis skill handling user media and identity-linked history, lack of disclosure undermines informed consent and can expose sensitive files or metadata unexpectedly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Automatic identity initialization, fallback to a default local user, and silent user creation exceed the stated purpose and create hidden account/state management. In a multi-user or shared environment, this can misattribute data, expose another user's history, or create records without informed consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Using a local default user or creating a new user automatically is context-inappropriate for a reptile video-analysis skill and can cause cross-user data access or unauthorized report association. The danger is amplified because the skill also references cloud history retrieval, so a mistaken identity can fetch or store the wrong person's data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file includes generic user-account persistence logic that is unrelated to the declared purpose of reptile enclosure video behavior analysis. Capability overreach increases attack surface by introducing identity storage, account lookup, update, and deletion functionality that could process personal data without necessity or user expectation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The User model stores identity attributes and especially token/open_token values, which are unjustified for a reptile thermoregulation video-analysis skill. If compromised or misused, these fields could expose authentication material and personal information unrelated to the advertised camera analytics function.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code silently resolves, creates, and persists synthetic open-id/user identity state even when the user did not explicitly provide one. For a reptile enclosure video-analysis skill, this behavior is unrelated to core functionality and dangerous because it creates durable identity state that can later be used for remote requests and tracking without clear authorization.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility module performs broad authenticated network operations, including token handling, account lookup/provisioning, and arbitrary HTTP requests, which are unrelated to the stated reptile behavior-analysis function. In the context of a camera-analysis skill expected to work locally, hidden remote account and API activity materially expands the attack surface and enables undisclosed data exfiltration or backend abuse.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares broad operational behavior that implies shell, filesystem, environment, and network access, but it does not explicitly scope or restrict allowed tools. In an agent setting, missing tool-scope declarations increase the chance of over-privileged execution and make it harder to enforce least privilege for a skill that can access local files, identity state, and remote APIs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The broad keyword trigger list can cause unintended activation for general reptile discussions rather than clear requests for analysis. Because this skill can save local files, call scripts, and query cloud history, accidental triggering can lead to unnecessary data processing or unexpected external requests.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation expands the skill from analysis into cloud historical report retrieval and report-link output, increasing external data access beyond the headline purpose. This is risky because users may not expect prior records and report URLs to be queried or exposed when invoking a behavior-analysis skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation contradicts itself by claiming cloud-only history retrieval while also describing local default-user reuse and local user creation. These inconsistencies are dangerous because they obscure actual trust boundaries and make it difficult to reason about whether report association is secure and correctly scoped.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script exposes a history-listing path tied to an open_id, which extends beyond simple one-shot video analysis into account-scoped data access. In this file, there is no visible authorization check, user disclosure, or scope restriction before retrieving historical reports, creating a risk of unintended access to prior analysis data if identity handling elsewhere is weak or spoofable.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code initializes an internal account identity via OpenIdUtil and accepts a hidden --open-id argument suppressed from help, which is not justified by the stated reptile video-analysis purpose. Hidden identity plumbing increases the chance of stealthy account-context operations and can enable unauthorized data access or cross-user confusion if callers can influence the identity value.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2