Back to skill

Security audit

Pet Sneeze / Cough Detection | 宠物睡眠质量分析(时长/翻滚次数)

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to perform the advertised cloud pet-video analysis, but it also silently creates or reuses identities, stores tokens locally, and is configured to send sensitive data over cleartext development endpoints.

Install only if you are comfortable sending pet rest-area videos and report-history requests to this publisher's cloud service, and only after the publisher removes the dev HTTP configuration, documents the data flow, obtains explicit consent for uploads and history access, and replaces plaintext token persistence with secure scoped credential handling.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/config-dev.yaml:2
Finding

Pet videos, identity data, and authentication credentials may be transmitted over cleartext HTTP

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
skills/smyx_common/scripts/util.py:553
Finding

Agent identity is silently collected and registered with an external service

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/util.py:586
Finding

Reusable authentication tokens are stored in a plaintext workspace SQLite database

Content
View full analysis
T: session = self.get_session() try: session.add(model) session.commit() session.refresh(model) return model finally: session.close() ``` ```python # skills/smyx_common/scripts/dao.py token = Column(String(500), comment="token") open_token = Column(String(1000), comment="open token") ``` ### Technical Analysis Tokens returned by the external registration service are copied into a `User` model and committed to `data/smyx-common-claw.db`. The database is ordinary SQLite storage, and the audited code does not encrypt the token fields or expl ...[truncated 1533 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skills/smyx_analysis/requirements.txt:3
Finding

Incorrect dependency name creates dependency-confusion and package-substitution risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (56)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The detected implementation reportedly handles network communication, local files, directory creation, identity/open-id generation, and database records while lacking any actual pet sleep analysis logic. In this context, that combination strongly suggests overcollection and hidden persistence of sensitive user and media data under a misleading functional description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The detected implementation reportedly handles network communication, local files, directory creation, identity/open-id generation, and database records while lacking any actual pet sleep analysis logic. In this context, that combination strongly suggests overcollection and hidden persistence of sensitive user and media data under a misleading functional description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The detected implementation reportedly handles network communication, local files, directory creation, identity/open-id generation, and database records while lacking any actual pet sleep analysis logic. In this context, that combination strongly suggests overcollection and hidden persistence of sensitive user and media data under a misleading functional description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The detected implementation reportedly handles network communication, local files, directory creation, identity/open-id generation, and database records while lacking any actual pet sleep analysis logic. In this context, that combination strongly suggests overcollection and hidden persistence of sensitive user and media data under a misleading functional description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The detected implementation reportedly handles network communication, local files, directory creation, identity/open-id generation, and database records while lacking any actual pet sleep analysis logic. In this context, that combination strongly suggests overcollection and hidden persistence of sensitive user and media data under a misleading functional description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The detected implementation reportedly handles network communication, local files, directory creation, identity/open-id generation, and database records while lacking any actual pet sleep analysis logic. In this context, that combination strongly suggests overcollection and hidden persistence of sensitive user and media data under a misleading functional description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The detected implementation reportedly handles network communication, local files, directory creation, identity/open-id generation, and database records while lacking any actual pet sleep analysis logic. In this context, that combination strongly suggests overcollection and hidden persistence of sensitive user and media data under a misleading functional description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The detected implementation reportedly handles network communication, local files, directory creation, identity/open-id generation, and database records while lacking any actual pet sleep analysis logic. In this context, that combination strongly suggests overcollection and hidden persistence of sensitive user and media data under a misleading functional description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The detected implementation reportedly handles network communication, local files, directory creation, identity/open-id generation, and database records while lacking any actual pet sleep analysis logic. In this context, that combination strongly suggests overcollection and hidden persistence of sensitive user and media data under a misleading functional description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The detected implementation reportedly handles network communication, local files, directory creation, identity/open-id generation, and database records while lacking any actual pet sleep analysis logic. In this context, that combination strongly suggests overcollection and hidden persistence of sensitive user and media data under a misleading functional description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The detected implementation reportedly handles network communication, local files, directory creation, identity/open-id generation, and database records while lacking any actual pet sleep analysis logic. In this context, that combination strongly suggests overcollection and hidden persistence of sensitive user and media data under a misleading functional description.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-sleep-quality-analysis-analysis"
description: "AI-powered pet sleep quality analysis from a fixed bed/rest-area camera. Uses motion detection and pose recognition to distinguish sleeping vs. awake states, accumulates total sleep duration, counts roll-overs / position changes and startle-awakenings, and outputs a 0-100 sleep-quality score. Helps owners spot potential pain, anxiety, or disease early. Scenarios: home nighttime monitoring, senior pet health management, animal hospital wards, pet boarding centers. | 通过宠物窝或休息区固定摄像头,在夜间(或宠物主要睡眠时段)持续分析视频,利用�

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The User model stores personal profile attributes and especially token/open_token values inside a local SQLite database, which is unjustified for a pet sleep monitoring skill. Sensitive credential material and identifying data in a local file substantially raise the consequences of local file disclosure, backup leakage, or unauthorized workspace access.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The function's docstring and logging claim it invokes an external agent via subprocess, but the implementation instead assigns result: dict = {} and then accesses result.stderr and result.stdout, which will fail at runtime. This mismatch is dangerous because it obscures the true behavior, defeats review and monitoring expectations, and could hide a future swap-in of real command execution without corresponding security scrutiny.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code automatically resolves, creates, and persists default user identities for backend access, even when no explicit identity was provided by the user. For a camera-based sleep analysis skill, this is unjustified and dangerous because it silently establishes external identity linkage and enables later authenticated transmissions without informed user action.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The utility code performs remote account lookup/provisioning, token handling, and authenticated API calls that are unrelated to the declared local pet sleep-analysis purpose. In this skill context, hidden backend communication materially increases risk because user identity and telemetry may be transmitted off-device without necessity or clear consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises and operationalizes shell, file, environment, and network capabilities but does not declare an explicit tool/permission scope in the manifest. That creates an authority gap: reviewers and runtime policy cannot easily constrain what the skill may access, increasing the risk of unintended command execution, local file access, or remote data exfiltration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The default trigger activates on broadly phrased requests involving pet rest-area nighttime video, making accidental auto-execution more likely. Because the skill can save files locally and invoke networked analysis/history functions, an overbroad trigger raises the chance of unintended data handling or upload without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The history-report trigger uses everyday phrases like viewing past reports and automatically calls a cloud API, potentially exposing identity-linked historical records with minimal friction. In a health-adjacent, home-monitoring context, this is sensitive because users may not realize a casual request triggers remote retrieval of stored report metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow states that uploaded files may be saved locally and network URLs are submitted to an API service, but the skill description does not clearly warn users that their pet videos and URLs are transmitted to the cloud. This is particularly sensitive because home-monitoring footage can reveal private household details, routines, and location-linked metadata.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill’s stated purpose is local/video sleep-quality analysis, but the CLI also exposes a history-report listing function keyed to user identity via open_id. That creates an additional identity-scoped data access surface that is not clearly disclosed by the manifest, increasing the risk of unauthorized access to prior reports if identity resolution or backend authorization is weak.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest frames the skill as analyzing pet sleep from a fixed rest-area camera, which implies processing a designated local or known camera source. At L110-L116, the code explicitly accepts any HTTP/HTTPS URL as input and forwards it for analysis, broadening the skill from fixed-camera monitoring to generic remote video analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill reads arbitrary local file contents into memory and uploads them to an external analysis service with no user-facing warning, consent flow, or data-minimization controls in this file. In a skill handling user-provided paths, that creates a real privacy and data-exfiltration risk: users may unintentionally send sensitive local media or mislabeled files off-device.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2