Back to skill

Security audit

Seed Germination Rate Prediction Analysis | 种子发芽率早期预测

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real seed-germination analysis wrapper, but it silently creates or reuses user identity, registers/logs in to a remote service, and stores reusable tokens for future cloud report access.

Install only if you are comfortable with seed tray images or URLs being sent to the vendor's cloud service and with the skill creating/reusing a local identity plus stored service tokens for report history. Review or remove data/smyx-api-key.txt and the workspace SQLite database if you do not want persistent account linkage.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (56)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication handling, token/header injection, automatic remote login or user creation, local workspace discovery, and persistent default identity generation are all high-risk behaviors when hidden behind a simple seed-counting skill. This combination can silently bind user activity to remote accounts, expose local environment structure, and expand the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Authentication handling, token/header injection, automatic remote login or user creation, local workspace discovery, and persistent default identity generation are all high-risk behaviors when hidden behind a simple seed-counting skill. This combination can silently bind user activity to remote accounts, expose local environment structure, and expand the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Authentication handling, token/header injection, automatic remote login or user creation, local workspace discovery, and persistent default identity generation are all high-risk behaviors when hidden behind a simple seed-counting skill. This combination can silently bind user activity to remote accounts, expose local environment structure, and expand the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Authentication handling, token/header injection, automatic remote login or user creation, local workspace discovery, and persistent default identity generation are all high-risk behaviors when hidden behind a simple seed-counting skill. This combination can silently bind user activity to remote accounts, expose local environment structure, and expand the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Authentication handling, token/header injection, automatic remote login or user creation, local workspace discovery, and persistent default identity generation are all high-risk behaviors when hidden behind a simple seed-counting skill. This combination can silently bind user activity to remote accounts, expose local environment structure, and expand the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Authentication handling, token/header injection, automatic remote login or user creation, local workspace discovery, and persistent default identity generation are all high-risk behaviors when hidden behind a simple seed-counting skill. This combination can silently bind user activity to remote accounts, expose local environment structure, and expand the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authentication handling, token/header injection, automatic remote login or user creation, local workspace discovery, and persistent default identity generation are all high-risk behaviors when hidden behind a simple seed-counting skill. This combination can silently bind user activity to remote accounts, expose local environment structure, and expand the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication handling, token/header injection, automatic remote login or user creation, local workspace discovery, and persistent default identity generation are all high-risk behaviors when hidden behind a simple seed-counting skill. This combination can silently bind user activity to remote accounts, expose local environment structure, and expand the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authentication handling, token/header injection, automatic remote login or user creation, local workspace discovery, and persistent default identity generation are all high-risk behaviors when hidden behind a simple seed-counting skill. This combination can silently bind user activity to remote accounts, expose local environment structure, and expand the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication handling, token/header injection, automatic remote login or user creation, local workspace discovery, and persistent default identity generation are all high-risk behaviors when hidden behind a simple seed-counting skill. This combination can silently bind user activity to remote accounts, expose local environment structure, and expand the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication handling, token/header injection, automatic remote login or user creation, local workspace discovery, and persistent default identity generation are all high-risk behaviors when hidden behind a simple seed-counting skill. This combination can silently bind user activity to remote accounts, expose local environment structure, and expand the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication handling, token/header injection, automatic remote login or user creation, local workspace discovery, and persistent default identity generation are all high-risk behaviors when hidden behind a simple seed-counting skill. This combination can silently bind user activity to remote accounts, expose local environment structure, and expand the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authentication handling, token/header injection, automatic remote login or user creation, local workspace discovery, and persistent default identity generation are all high-risk behaviors when hidden behind a simple seed-counting skill. This combination can silently bind user activity to remote accounts, expose local environment structure, and expand the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The YARA hit for metadata poisoning indicators suggests suspicious or malformed manifest metadata, which can be used to manipulate tool selection, evade review, or smuggle misleading instructions into agent ecosystems. Given the broader pattern of description-behavior mismatch in this skill, such metadata anomalies are more concerning than they would be in an otherwise clean manifest.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-seed-germination-rate-prediction-analysis"
description: "Triggers when a user provides a seedling tray image or video for analysis; uses AI object detection to identify emerged seedlings (cotyledons breaking through soil or fully expanded), counts germinated seeds, and compares with total sown seeds to estimate germination rate. Application scenarios: smart seedling incubators, greenhouse nursery trays, home planting pots, seed company germination tests. | 通过育苗盘上方的固定摄像头,播种后连续采集土壤表面图像,利用AI目标检测模型识别出土幼苗,计数已发芽的种子数量,并与播种总数

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file defines a generic local user DAO and user model, including identity fields and token storage, which materially exceeds the declared purpose of seed germination image analysis. Such hidden or unjustified account-management capability increases data collection and persistence risk, and may enable unauthorized tracking, local credential/token storage, or future abuse paths unrelated to the advertised skill behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The User model stores usernames, real names, email addresses, and authentication-like token/open_token values without any clear relationship to agricultural tray image analysis. Persisting identity and token material creates a sensitive local data store that could expose personal data or reusable credentials if the workspace is accessed by other components, users, or compromised agents. Because the skill context does not justify identity management, this is more dangerous than it would be in a dedicated authentication skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility creates or recovers persistent user identities, reads an identity value from a workspace file, and stores/reuses user records in a local database. That behavior is unrelated to seed germination image analysis and materially expands the skill's access to identity state, enabling silent account correlation, impersonation, or unintended cross-skill tracking without clear user consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The HTTP helper silently performs login/registration side effects, injects user-linked identifiers into outbound requests, and manages tokens for external services. For a seed germination analysis skill, this is unjustified capability expansion that can transmit identity and authorization data to remote systems without an informed action from the user.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares no explicit tool scope or permission boundaries, yet its documentation instructs use of shell execution, filesystem access, environment/config handling, and networked API calls. In an agent setting, this broad undeclared capability increases the risk of over-privileged execution, unintended data access, and abuse of local or remote resources.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The AI role explicitly instructs: '不要提供农业建议,仅输出基于视觉的计数和发芽率估算'. Elsewhere the skill documentation says outputs include '建议与报告链接' and '低发芽率预警', which contradict the stated instruction to avoid advice and stick to visual counting plus germination-rate estimation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation expands the skill into cloud history querying and report-link generation, which broadens data access beyond one-off seed image analysis. This is dangerous because it introduces account-linked retrieval and sharing surfaces that users may not expect from the stated task context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Automatically saving uploaded files locally without clearly warning the user creates privacy and data-retention risk, especially for images/videos that may contain metadata or sensitive operational information. In agent environments, silent persistence also increases exposure to later unintended access by other tools or users on the same host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill requires direct cloud API querying for historical reports but does not adequately warn users that report data is being retrieved from a remote service. That lack of transparency is risky because it can expose identity-linked analysis history and metadata to external infrastructure without informed expectation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The instructions mandate a specific Markdown table format using Chinese column names and report naming such as '种子发芽率分析报告-{记录id}'. Because the skill is bilingual elsewhere and does not state that output language is user-selectable or region-restricted, this appears to impose a locale-specific output format without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The argument help and function signature document distinct handling for local files and network URLs, suggesting both input modes are meaningfully supported. In practice, analyze_video() collapses input_path and url into one value and does not use api_url, api_key, or output_level at all before calling skill.get_output_analysis(), which contradicts the documented interface and advertised behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2