Back to skill

Security audit

Real-time Employee Absence Monitoring Skill | 人员离岗实时监测技能

Security checks for vulnerabilities and agentic risk

Overview

This skill is a cloud-backed workplace surveillance analyzer that mostly matches its stated purpose, but it silently creates or reuses identity records, stores tokens locally, and sends sensitive media and identity data to external services with insufficient disclosure.

Review before installing. Only use this skill if you are comfortable sending workplace images/videos or media URLs, plus an internal user identity, to the lifeemergence.com/open.lifeemergence.com services. Ask the publisher for clear retention, authorization, account-creation, token-storage, and report-history access terms, and prefer a version that requires explicit confirmation before media upload or history queries.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (69)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented scope is narrow operational monitoring, but the code indicators include external HTTP communication, authentication/token handling, automatic account creation/login, workspace discovery, and local identity persistence. These capabilities materially increase attack surface and privacy risk because they enable remote service interaction and durable user correlation under a misleading label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented scope is narrow operational monitoring, but the code indicators include external HTTP communication, authentication/token handling, automatic account creation/login, workspace discovery, and local identity persistence. These capabilities materially increase attack surface and privacy risk because they enable remote service interaction and durable user correlation under a misleading label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented scope is narrow operational monitoring, but the code indicators include external HTTP communication, authentication/token handling, automatic account creation/login, workspace discovery, and local identity persistence. These capabilities materially increase attack surface and privacy risk because they enable remote service interaction and durable user correlation under a misleading label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented scope is narrow operational monitoring, but the code indicators include external HTTP communication, authentication/token handling, automatic account creation/login, workspace discovery, and local identity persistence. These capabilities materially increase attack surface and privacy risk because they enable remote service interaction and durable user correlation under a misleading label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented scope is narrow operational monitoring, but the code indicators include external HTTP communication, authentication/token handling, automatic account creation/login, workspace discovery, and local identity persistence. These capabilities materially increase attack surface and privacy risk because they enable remote service interaction and durable user correlation under a misleading label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented scope is narrow operational monitoring, but the code indicators include external HTTP communication, authentication/token handling, automatic account creation/login, workspace discovery, and local identity persistence. These capabilities materially increase attack surface and privacy risk because they enable remote service interaction and durable user correlation under a misleading label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented scope is narrow operational monitoring, but the code indicators include external HTTP communication, authentication/token handling, automatic account creation/login, workspace discovery, and local identity persistence. These capabilities materially increase attack surface and privacy risk because they enable remote service interaction and durable user correlation under a misleading label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented scope is narrow operational monitoring, but the code indicators include external HTTP communication, authentication/token handling, automatic account creation/login, workspace discovery, and local identity persistence. These capabilities materially increase attack surface and privacy risk because they enable remote service interaction and durable user correlation under a misleading label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented scope is narrow operational monitoring, but the code indicators include external HTTP communication, authentication/token handling, automatic account creation/login, workspace discovery, and local identity persistence. These capabilities materially increase attack surface and privacy risk because they enable remote service interaction and durable user correlation under a misleading label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented scope is narrow operational monitoring, but the code indicators include external HTTP communication, authentication/token handling, automatic account creation/login, workspace discovery, and local identity persistence. These capabilities materially increase attack surface and privacy risk because they enable remote service interaction and durable user correlation under a misleading label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented scope is narrow operational monitoring, but the code indicators include external HTTP communication, authentication/token handling, automatic account creation/login, workspace discovery, and local identity persistence. These capabilities materially increase attack surface and privacy risk because they enable remote service interaction and durable user correlation under a misleading label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented scope is narrow operational monitoring, but the code indicators include external HTTP communication, authentication/token handling, automatic account creation/login, workspace discovery, and local identity persistence. These capabilities materially increase attack surface and privacy risk because they enable remote service interaction and durable user correlation under a misleading label.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "staff-absence-detection-analysis"
description: "Real-time monitoring of personnel on-duty status in specific areas based on computer vision and human pose estimation, automatically detects abnormal statuses such as leaving posts and absent from work, supports custom threshold settings, and triggers early warning immediately when abnormality is detected. | 人员离岗实时监测技能,基于计算机视觉与人体姿态估计算法,实时监测特定区域内人员的在岗状态,自动判断离岗、缺岗等异常状态,支持自定义判定阈值,异常发生立即触发预警,适用于工厂车间、监控室

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The fallback behavior creates persistent local user identities and stores them for later API use without a clear business need tied to absence detection. This expands the skill into identity creation and persistence, which can enable unauthorized account sprawl, attribution confusion, and hidden external service usage.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The utility layer performs token bootstrap, account lookup, and remote account provisioning/login flows that are unrelated to the stated staff-absence detection purpose. This creates an unexpected identity-management and outbound-authentication capability, increasing the chance of covert data transmission, account abuse, and use of the host environment's stored identity material.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill documents behaviors that require shell, filesystem, network, and environment access, but it does not declare any explicit tool scope or permissions boundaries. This creates an overbroad and opaque execution surface where the agent may invoke powerful capabilities without user-visible constraints, increasing the risk of unintended file access, command execution, or network egress.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest framing emphasizes real-time monitoring, while the documentation also adds historical cloud report retrieval and report-link browsing. Undeclared secondary capabilities can surprise users and reviewers, especially when they involve remote data access and potentially sensitive past reports.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are broad enough to auto-activate on generic references to monitoring or report history, which can cause unintended execution. In a skill that can save files locally and contact cloud APIs, accidental activation increases the chance of unnecessary data processing or disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill includes cloud historical report querying and persistent user identity handling that exceed the stated real-time analysis purpose. This scope expansion matters because it introduces privacy-sensitive longitudinal data access and identity correlation without clear need or narrowly defined authorization boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill states that uploaded attachments are automatically saved as local files without a clear user warning. Silent local persistence of user-provided media can create privacy, retention, and forensic exposure risks, especially for surveillance footage or workplace images.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation does not clearly warn that historical report queries use a cloud API and that network media URLs may be fetched remotely. This matters because users may unintentionally send sensitive operational media or query metadata to third-party services without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that personnel images/videos and an open_id are sent to a cloud API, but it does not clearly disclose the privacy and security implications of transmitting potentially sensitive workplace surveillance data to a remote service. In this skill context, the data involves employee monitoring and status analysis, which makes omission of data-handling, retention, and consent guidance more dangerous than a generic API integration issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The method returns a fixed Chinese string for analysis output, with no indication that users can choose their preferred language or locale. This creates a natural-language policy concern because the skill appears to enforce one language unconditionally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's natural-language strings, CLI descriptions, errors, and status messages are consistently hardcoded in Chinese. This forces a specific language for all users without offering a language selection or documenting a justified locale restriction, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script exposes behavior beyond the advertised absence-detection function by allowing history listing tied to an internal user identity (show_analyze_list) and by resolving an OpenID in a non-transparent way. In a monitoring/surveillance context, hidden identity-linked retrieval increases privacy risk and can enable access to prior analysis data without clear user awareness or authorization boundaries.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2