Back to skill

Security audit

Pet Sneeze / Cough Detection | 宠物打喷嚏/咳嗽检测

Security checks for vulnerabilities and agentic risk

Overview

The skill’s pet cough/sneeze analysis is plausible, but it sends media to a cloud service while silently creating or reusing a persistent identity and token-backed report history.

Install only if you are comfortable sending pet videos, possible household audio/interiors, and report history to the Life Emergence cloud service. Review how the service handles retention, account identity, and deletion before using this for sensitive home, clinic, or boarding-center footage.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (52)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

External HTTP communication, token management, automatic account creation/login, local key/open-id access, and database-backed user lookup substantially exceed the declared media-analysis purpose. In a health-adjacent workflow, undisclosed identity and credential handling materially increases privacy, data-leakage, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

External HTTP communication, token management, automatic account creation/login, local key/open-id access, and database-backed user lookup substantially exceed the declared media-analysis purpose. In a health-adjacent workflow, undisclosed identity and credential handling materially increases privacy, data-leakage, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

External HTTP communication, token management, automatic account creation/login, local key/open-id access, and database-backed user lookup substantially exceed the declared media-analysis purpose. In a health-adjacent workflow, undisclosed identity and credential handling materially increases privacy, data-leakage, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

External HTTP communication, token management, automatic account creation/login, local key/open-id access, and database-backed user lookup substantially exceed the declared media-analysis purpose. In a health-adjacent workflow, undisclosed identity and credential handling materially increases privacy, data-leakage, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, token management, automatic account creation/login, local key/open-id access, and database-backed user lookup substantially exceed the declared media-analysis purpose. In a health-adjacent workflow, undisclosed identity and credential handling materially increases privacy, data-leakage, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, token management, automatic account creation/login, local key/open-id access, and database-backed user lookup substantially exceed the declared media-analysis purpose. In a health-adjacent workflow, undisclosed identity and credential handling materially increases privacy, data-leakage, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, token management, automatic account creation/login, local key/open-id access, and database-backed user lookup substantially exceed the declared media-analysis purpose. In a health-adjacent workflow, undisclosed identity and credential handling materially increases privacy, data-leakage, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, token management, automatic account creation/login, local key/open-id access, and database-backed user lookup substantially exceed the declared media-analysis purpose. In a health-adjacent workflow, undisclosed identity and credential handling materially increases privacy, data-leakage, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, token management, automatic account creation/login, local key/open-id access, and database-backed user lookup substantially exceed the declared media-analysis purpose. In a health-adjacent workflow, undisclosed identity and credential handling materially increases privacy, data-leakage, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, token management, automatic account creation/login, local key/open-id access, and database-backed user lookup substantially exceed the declared media-analysis purpose. In a health-adjacent workflow, undisclosed identity and credential handling materially increases privacy, data-leakage, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, token management, automatic account creation/login, local key/open-id access, and database-backed user lookup substantially exceed the declared media-analysis purpose. In a health-adjacent workflow, undisclosed identity and credential handling materially increases privacy, data-leakage, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-sneeze-cough-detection-analysis"
description: "AI-powered pet sneeze/cough detection from real-time camera (optional audio fusion). Analyzes head and thoracic-abdominal motion plus sound features to distinguish single occasional events (normal airway clearing) from continuous bursts (e.g. ≥3 sneezes/min, frequent dry/wet coughing) and records event time and frequency. Helps catch respiratory infection, allergy, or foreign-body irritation early. Scenarios: home health monitoring, animal hospital wards, pet boarding centers. | 通过宠物摄像头实时分析宠物头部和胸腹部的动作,结合可选的声音分析,�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility performs account provisioning, token retrieval/storage, and authenticated API communication that are unrelated to pet sneeze/cough detection. In a camera/audio analysis skill, hidden identity bootstrapping and remote account operations materially expand the trust boundary, create undisclosed data flows, and could bind the user's environment to external services without informed consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares no explicit tool scope or permissions while its documented behavior requires shell execution, file access, network access, and environment usage. This weakens least-privilege controls and makes it easier for the skill to invoke capabilities beyond what a reviewer or runtime policy may expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

A default trigger on generic pet-video analysis requests is overly broad and can cause the skill to activate in situations where users did not intend respiratory monitoring or remote processing. Over-triggering increases the chance of unnecessary file handling, network transmission, and accidental exposure of unrelated media.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Broad medical keywords like cough, allergy, rhinitis, or kennel cough without tight scope constraints can trigger the skill for loosely related health discussions. In combination with file and network capabilities, this increases the risk of over-collection and unintended invocation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Automatically creating or reusing a local default identity without explicit user awareness is risky because it silently links analyses and report history to a persistent account context. In a monitoring skill handling potentially sensitive animal-health videos, this can cause privacy leakage, mistaken attribution, or unauthorized cross-session access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script resolves an internal user identity via OpenIdUtil.resolve_current_open_id() without clearly disclosing this behavior to the user, and the related --open-id parameter is suppressed from help output. In a health-monitoring context that stores and lists historical reports, hidden identity binding can cause analysis data to be associated with an unexpected account or expose another user's report history, making this a genuine privacy and authorization concern.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Several returned strings are fixed in Chinese, such as the report header and export-link text, with no visible option for the user to select another language. This is a natural-language locale policy concern because the skill imposes a specific language rather than offering choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The no-result message is returned only in Chinese and does not appear to respect user locale or provide opt-in. This continues the pattern of forcing a single language in user-visible responses.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes behavior centered on detecting pet sneezing/coughing patterns from motion and optional audio, including distinguishing isolated versus continuous events and recording frequency. In this implementation, the code performs input validation, optional file upload or URL passing, polling, and report rendering, but contains no code that implements the described detection or event-frequency analysis itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code reads the entire local file and sends it to an external analysis service, or forwards a remote video URL for backend retrieval, without any visible notice, consent flow, or data-handling disclosure in this component. In a pet-monitoring context, uploaded video may contain sensitive household interiors, people, audio, or location-linked behavioral data, creating privacy and compliance risk if users are unaware of transmission to a backend.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The analysis-records list heading and empty-state message are fixed in Chinese with no visible locale selection. This is a policy issue under the language/locale rule because the skill does not offer user choice.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2