Back to skill

Security audit

Rose Pest & Disease Detection | 月季/玫瑰常见病虫害识别

Security checks for vulnerabilities and agentic risk

Overview

The skill is presented as rose pest detection, but it also performs cloud account/session handling, token persistence, and history lookup with unclear user control.

Review this skill before installing. It may upload user-provided plant media or URLs to a third-party cloud service, silently create or reuse an account identity, fetch account-linked report history, and store authentication tokens locally in the workspace data directory. Install only if that account linkage and persistence model is acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (64)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The findings describe a broad set of hidden behaviors: local file and directory access, environment detection, identity creation and persistence, authenticated HTTP requests, token refresh, and remote login/registration flows. Under the cover of a rose-disease detector, these capabilities could enable silent account linkage, data exfiltration, and access to prior records, making the benign skill context materially more dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The findings describe a broad set of hidden behaviors: local file and directory access, environment detection, identity creation and persistence, authenticated HTTP requests, token refresh, and remote login/registration flows. Under the cover of a rose-disease detector, these capabilities could enable silent account linkage, data exfiltration, and access to prior records, making the benign skill context materially more dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The findings describe a broad set of hidden behaviors: local file and directory access, environment detection, identity creation and persistence, authenticated HTTP requests, token refresh, and remote login/registration flows. Under the cover of a rose-disease detector, these capabilities could enable silent account linkage, data exfiltration, and access to prior records, making the benign skill context materially more dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The findings describe a broad set of hidden behaviors: local file and directory access, environment detection, identity creation and persistence, authenticated HTTP requests, token refresh, and remote login/registration flows. Under the cover of a rose-disease detector, these capabilities could enable silent account linkage, data exfiltration, and access to prior records, making the benign skill context materially more dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The findings describe a broad set of hidden behaviors: local file and directory access, environment detection, identity creation and persistence, authenticated HTTP requests, token refresh, and remote login/registration flows. Under the cover of a rose-disease detector, these capabilities could enable silent account linkage, data exfiltration, and access to prior records, making the benign skill context materially more dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The findings describe a broad set of hidden behaviors: local file and directory access, environment detection, identity creation and persistence, authenticated HTTP requests, token refresh, and remote login/registration flows. Under the cover of a rose-disease detector, these capabilities could enable silent account linkage, data exfiltration, and access to prior records, making the benign skill context materially more dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The findings describe a broad set of hidden behaviors: local file and directory access, environment detection, identity creation and persistence, authenticated HTTP requests, token refresh, and remote login/registration flows. Under the cover of a rose-disease detector, these capabilities could enable silent account linkage, data exfiltration, and access to prior records, making the benign skill context materially more dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The findings describe a broad set of hidden behaviors: local file and directory access, environment detection, identity creation and persistence, authenticated HTTP requests, token refresh, and remote login/registration flows. Under the cover of a rose-disease detector, these capabilities could enable silent account linkage, data exfiltration, and access to prior records, making the benign skill context materially more dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The findings describe a broad set of hidden behaviors: local file and directory access, environment detection, identity creation and persistence, authenticated HTTP requests, token refresh, and remote login/registration flows. Under the cover of a rose-disease detector, these capabilities could enable silent account linkage, data exfiltration, and access to prior records, making the benign skill context materially more dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The findings describe a broad set of hidden behaviors: local file and directory access, environment detection, identity creation and persistence, authenticated HTTP requests, token refresh, and remote login/registration flows. Under the cover of a rose-disease detector, these capabilities could enable silent account linkage, data exfiltration, and access to prior records, making the benign skill context materially more dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The findings describe a broad set of hidden behaviors: local file and directory access, environment detection, identity creation and persistence, authenticated HTTP requests, token refresh, and remote login/registration flows. Under the cover of a rose-disease detector, these capabilities could enable silent account linkage, data exfiltration, and access to prior records, making the benign skill context materially more dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The findings describe a broad set of hidden behaviors: local file and directory access, environment detection, identity creation and persistence, authenticated HTTP requests, token refresh, and remote login/registration flows. Under the cover of a rose-disease detector, these capabilities could enable silent account linkage, data exfiltration, and access to prior records, making the benign skill context materially more dangerous.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-rose-pest-disease-detection-analysis"
description: "AI-powered pest & disease detection for roses (Rosa spp.). From garden cameras or mobile phone images of leaves, young shoots and flower buds, detects common rose enemies including black spot (black round/irregular spots with yellow halo), powdery mildew (white powdery layer on leaves/shoots), spider mites (tiny red/white dots on leaf back with webbing in severe cases) and aphids (green/black clustered tiny insects on shoots and buds). Outputs pest/disease type, severity grade and general control suggestions. Helps gardeners detect issues early and act in time. Scenarios: home ga

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes analysis of rose leaf/shoot/bud images from cameras or phones, but this code explicitly requires either a local video path or a network video URL and places the input into a 'videoUrl' parameter. That is a semantic mismatch in the skill's claimed modality and behavior, not a mere implementation detail.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The implementation materially diverges from the advertised skill purpose: instead of rose pest/disease image detection, it acts as a generic video analysis client and can also retrieve analysis history. This is dangerous because users and platform reviewers may grant permissions or trust based on the manifest, while the code performs broader remote processing than expected, creating a deception and misuse risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The CLI description, argument help, and function docstrings consistently describe a generic 'video analysis tool,' directly contradicting the skill's stated rose image diagnostic purpose. This mismatch is dangerous because it masks actual behavior from users and reviewers, increasing the chance that unrelated or privacy-impacting functionality is deployed under a misleading label.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The model stores authentication-like tokens together with profile data such as username, real name, email, birthday, sex, and age, but the skill’s stated purpose is plant disease detection from images. Collecting and persisting this data without clear necessity violates data minimization principles and raises the impact of local database compromise or unintended cross-skill access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The utility code provisions remote user accounts, fetches tokens, and persists them locally, which is far beyond what an image-based rose pest/disease detection skill needs. This creates hidden identity management and network side effects, increasing the chance of unauthorized account creation, token exposure, and covert platform access using the user's environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The HTTP helper transmits usernames, open IDs, tenant data, tokens, and platform metadata over the network without explicit user disclosure. In a rose pest detection skill, this hidden identity and token propagation is especially concerning because the declared function does not require broad account orchestration or background credential exchange.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares no explicit tool scope while its documented behavior includes shell execution, network access, local file writes, and environment use. In an agent ecosystem this creates an unnecessary capability gap between what users can infer and what the skill can actually do, increasing the chance of unintended data access or command execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill asks users to provide local files or URLs for analysis but does not clearly warn that those inputs may be transmitted to a cloud API service. This undermines informed consent and can expose private media, location hints, or embedded metadata to third-party processing unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Broad trigger phrases for historical report lookup can cause the skill to invoke cloud history retrieval when a user is only speaking generally about reports or past issues. Because the feature is identity-linked and remote, accidental triggering may disclose or fetch sensitive prior records without sufficiently clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill states that attachments are automatically saved as local files without clearly warning users about local persistence. Silent local storage increases risk of residual sensitive data on disk, especially in shared agent environments or systems with broad workspace access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented API endpoints and scenario code clearly describe a pet health analysis service, which does not match the declared rose pest/disease detection purpose of the skill. This kind of domain mismatch can cause the skill to call the wrong backend, expose unrelated data, or misroute user inputs and outputs, making the integration unsafe and unreliable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code presents the tool description, argument help text, and user-facing status/error messages in Chinese only. The file does not offer a user language/locale option or explain that the skill is intentionally restricted to a Chinese-speaking or region-specific context, which is a natural-language policy issue under the locale-choice rule.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2