Back to skill

Security audit

Plant Root Health Analysis (Transparent Pot) | 植物根系健康状况(透明盆)

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a cloud-backed plant-root analyzer, but it silently creates or reuses a service identity and stores account tokens locally, which users should review before installing.

Install only if you are comfortable sending plant images/videos or URLs to the Life Emergence cloud service and allowing the skill to silently create or reuse a local service identity, store tokens in workspace data, and fetch account-linked historical reports. Avoid using it with sensitive imagery or shared workspaces unless you have reviewed the local data and account behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (66)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents a narrow plant-root vision analyzer, but the documented behavior expands into hidden identity handling, history retrieval, generic backend access, storage interactions, and report export flows. This mismatch is dangerous because it can mislead reviewers and users about what data is accessed and what actions are performed, enabling unexpected collection of user-linked records and broader system interaction than the manifest suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents a narrow plant-root vision analyzer, but the documented behavior expands into hidden identity handling, history retrieval, generic backend access, storage interactions, and report export flows. This mismatch is dangerous because it can mislead reviewers and users about what data is accessed and what actions are performed, enabling unexpected collection of user-linked records and broader system interaction than the manifest suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents a narrow plant-root vision analyzer, but the documented behavior expands into hidden identity handling, history retrieval, generic backend access, storage interactions, and report export flows. This mismatch is dangerous because it can mislead reviewers and users about what data is accessed and what actions are performed, enabling unexpected collection of user-linked records and broader system interaction than the manifest suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents a narrow plant-root vision analyzer, but the documented behavior expands into hidden identity handling, history retrieval, generic backend access, storage interactions, and report export flows. This mismatch is dangerous because it can mislead reviewers and users about what data is accessed and what actions are performed, enabling unexpected collection of user-linked records and broader system interaction than the manifest suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents a narrow plant-root vision analyzer, but the documented behavior expands into hidden identity handling, history retrieval, generic backend access, storage interactions, and report export flows. This mismatch is dangerous because it can mislead reviewers and users about what data is accessed and what actions are performed, enabling unexpected collection of user-linked records and broader system interaction than the manifest suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents a narrow plant-root vision analyzer, but the documented behavior expands into hidden identity handling, history retrieval, generic backend access, storage interactions, and report export flows. This mismatch is dangerous because it can mislead reviewers and users about what data is accessed and what actions are performed, enabling unexpected collection of user-linked records and broader system interaction than the manifest suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents a narrow plant-root vision analyzer, but the documented behavior expands into hidden identity handling, history retrieval, generic backend access, storage interactions, and report export flows. This mismatch is dangerous because it can mislead reviewers and users about what data is accessed and what actions are performed, enabling unexpected collection of user-linked records and broader system interaction than the manifest suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents a narrow plant-root vision analyzer, but the documented behavior expands into hidden identity handling, history retrieval, generic backend access, storage interactions, and report export flows. This mismatch is dangerous because it can mislead reviewers and users about what data is accessed and what actions are performed, enabling unexpected collection of user-linked records and broader system interaction than the manifest suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents a narrow plant-root vision analyzer, but the documented behavior expands into hidden identity handling, history retrieval, generic backend access, storage interactions, and report export flows. This mismatch is dangerous because it can mislead reviewers and users about what data is accessed and what actions are performed, enabling unexpected collection of user-linked records and broader system interaction than the manifest suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents a narrow plant-root vision analyzer, but the documented behavior expands into hidden identity handling, history retrieval, generic backend access, storage interactions, and report export flows. This mismatch is dangerous because it can mislead reviewers and users about what data is accessed and what actions are performed, enabling unexpected collection of user-linked records and broader system interaction than the manifest suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents a narrow plant-root vision analyzer, but the documented behavior expands into hidden identity handling, history retrieval, generic backend access, storage interactions, and report export flows. This mismatch is dangerous because it can mislead reviewers and users about what data is accessed and what actions are performed, enabling unexpected collection of user-linked records and broader system interaction than the manifest suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents a narrow plant-root vision analyzer, but the documented behavior expands into hidden identity handling, history retrieval, generic backend access, storage interactions, and report export flows. This mismatch is dangerous because it can mislead reviewers and users about what data is accessed and what actions are performed, enabling unexpected collection of user-linked records and broader system interaction than the manifest suggests.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-root-health-transparent-pot-analysis"
description: "AI-powered plant root health analysis from transparent pots or smart seedling boxes. Uses fixed cameras to capture images/videos of plant roots, identifies root tip color (white=active, brown=aging, black=rotten), root hair density, branching structure, and detects root rot symptoms (softness, mucus, blackish-brown color). Outputs a root health score (0-100) and vitality grade (Healthy/Normal/Weak/Rotten). Helps early detection of root issues (overwatering rot, fertilizer burn, pathogen infection) and guides care adjustments. Scenarios: smart seedling boxes, transparent pots, pla

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation does not perform the plant root health analysis promised by the skill metadata and instead acts as a generic video-analysis/history wrapper. This kind of semantic mismatch is dangerous because users and downstream agents may trust the skill for domain-specific diagnosis while their media is sent to an unrelated backend, creating risk of privacy exposure, incorrect agricultural decisions, and deceptive capability claims.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file defines a full user-account DAO and default-user selection logic, which is materially unrelated to the declared root-health image analysis function. This mismatch expands the skill's data-handling scope to identity and account persistence without clear necessity, increasing privacy and abuse risk if the skill or its dependencies are invoked in unexpected ways.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The User model stores username, real name, email, birthday, age, token, and open_token, none of which are justified by the plant-root analysis use case. Collecting and updating identity plus token data creates unnecessary exposure of personal and authentication-related information, which could be abused or leaked if the local database is accessed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This utility code creates or reuses user identities, reads a local identity file, and persists default accounts even though the advertised skill is root-health image analysis. That hidden identity provisioning expands the skill's trust boundary and can cause undisclosed account creation and linkage of workspace activity to remote services without user awareness.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The HTTP helper silently performs remote login/registration behavior, injects tokens and usernames into requests, and retries authorization automatically against external service endpoints. For a plant root analysis skill, this is unrelated functionality that can transmit identifiers and establish remote accounts without transparent disclosure, increasing privacy and abuse risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises and instructs use of shell, file, network, and environment-dependent functionality but does not declare any explicit tool scope or allowed-tools boundary. This increases the blast radius of the skill because an agent may grant broader capabilities than necessary, making misuse of local files, shell execution, or outbound network access harder to constrain and audit.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest claims a visual root-health analysis skill, but the documentation also defines a cloud-backed historical report lookup capability. This hidden scope expansion can expose prior user-linked records without clear up-front disclosure, weakening informed consent and increasing the chance of privacy-sensitive data access beyond the user's immediate request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation says uploaded attachments are automatically saved as local files but does not prominently warn users about this retention behavior. Silent local persistence creates privacy and integrity risks, especially if the workspace is shared, backed up, or later accessed by other tools or sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill automatically performs cloud API queries and historical report retrieval without an explicit privacy or integrity warning. This can cause users to unknowingly send media or retrieve account-linked records from remote services, increasing risks around data exposure, consent, and trust in returned cloud data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill scope extends into automatic user identity management and default-account creation, which is unrelated to simple plant image analysis. Hidden identity lifecycle management is risky because it creates persistent user linkage and state that users and reviewers may not expect, potentially enabling cross-session data access and privacy issues.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatic creation and reuse of a local default user introduces persistent account behavior unrelated to plant analysis. If exploited or misconfigured, it could cause one user's reports to be associated with another session or expose historical records through a shared implicit identity.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Documenting a plant-analysis parameter as --pet-type with values like cat/dog/other indicates probable code reuse from another domain and undermines trust in the declared function. While not directly exploitable alone, this kind of mismatch is a strong indicator of incorrectly wired logic, wrong backend routing, or accidental processing under an unrelated model or policy path.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2