Back to skill

Security audit

Stranger Proximity Alert Skill | 陌生人靠近预警技能

Security checks for vulnerabilities and agentic risk

Overview

This skill handles sensitive child-monitoring media through a cloud service while silently creating and reusing persistent identities and tokens.

Review this carefully before installing. It may upload surveillance images or videos, including footage of minors, to external services and may create or reuse a persistent backend identity while storing tokens locally. Install only if you trust the publisher and service, have authority and consent for monitoring, and accept the cloud storage, history lookup, and identity persistence behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (58)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of external API communication, automatic account creation/login, token handling, local filesystem access, and database-backed identity persistence is materially broader than the declared child-safety function. In a surveillance-of-minors context, undisclosed identity resolution and persistence are especially dangerous because they can tie sensitive media and reports to hidden accounts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of external API communication, automatic account creation/login, token handling, local filesystem access, and database-backed identity persistence is materially broader than the declared child-safety function. In a surveillance-of-minors context, undisclosed identity resolution and persistence are especially dangerous because they can tie sensitive media and reports to hidden accounts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of external API communication, automatic account creation/login, token handling, local filesystem access, and database-backed identity persistence is materially broader than the declared child-safety function. In a surveillance-of-minors context, undisclosed identity resolution and persistence are especially dangerous because they can tie sensitive media and reports to hidden accounts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of external API communication, automatic account creation/login, token handling, local filesystem access, and database-backed identity persistence is materially broader than the declared child-safety function. In a surveillance-of-minors context, undisclosed identity resolution and persistence are especially dangerous because they can tie sensitive media and reports to hidden accounts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of external API communication, automatic account creation/login, token handling, local filesystem access, and database-backed identity persistence is materially broader than the declared child-safety function. In a surveillance-of-minors context, undisclosed identity resolution and persistence are especially dangerous because they can tie sensitive media and reports to hidden accounts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of external API communication, automatic account creation/login, token handling, local filesystem access, and database-backed identity persistence is materially broader than the declared child-safety function. In a surveillance-of-minors context, undisclosed identity resolution and persistence are especially dangerous because they can tie sensitive media and reports to hidden accounts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The combination of external API communication, automatic account creation/login, token handling, local filesystem access, and database-backed identity persistence is materially broader than the declared child-safety function. In a surveillance-of-minors context, undisclosed identity resolution and persistence are especially dangerous because they can tie sensitive media and reports to hidden accounts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of external API communication, automatic account creation/login, token handling, local filesystem access, and database-backed identity persistence is materially broader than the declared child-safety function. In a surveillance-of-minors context, undisclosed identity resolution and persistence are especially dangerous because they can tie sensitive media and reports to hidden accounts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of external API communication, automatic account creation/login, token handling, local filesystem access, and database-backed identity persistence is materially broader than the declared child-safety function. In a surveillance-of-minors context, undisclosed identity resolution and persistence are especially dangerous because they can tie sensitive media and reports to hidden accounts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of external API communication, automatic account creation/login, token handling, local filesystem access, and database-backed identity persistence is materially broader than the declared child-safety function. In a surveillance-of-minors context, undisclosed identity resolution and persistence are especially dangerous because they can tie sensitive media and reports to hidden accounts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of external API communication, automatic account creation/login, token handling, local filesystem access, and database-backed identity persistence is materially broader than the declared child-safety function. In a surveillance-of-minors context, undisclosed identity resolution and persistence are especially dangerous because they can tie sensitive media and reports to hidden accounts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The combination of external API communication, automatic account creation/login, token handling, local filesystem access, and database-backed identity persistence is materially broader than the declared child-safety function. In a surveillance-of-minors context, undisclosed identity resolution and persistence are especially dangerous because they can tie sensitive media and reports to hidden accounts.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "stranger-approach-warning-analysis"
description: "Detects the appearance of strangers near minors and actively issues safety reminder alerts to protect minor safety, suitable for homes, schools, childcare centers, and other scenarios. | 陌生人靠近预警技能,检测未成年人身边出现陌生人员,主动发出安全提醒预警,守护未成年人安全,适用于家庭、学校、托管场所等场景"
version: "1.0.20"
license: "MIT-0"
---

# 🚶 Stranger Proximity Alert Skill | 陌生人靠近预警技能
> **智能分析中枢** · 图片/视频智能分析 · 结构化报告 · 历史报告云端查询

---

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The implementation is a generic file/URL submission wrapper around a backend analysis service and does not enforce the manifest’s claimed safety-specific purpose of detecting strangers near minors. This mismatch can mislead users and integrators about what data is collected and what protections are actually being performed, increasing the chance of inappropriate deployment in sensitive child-safety contexts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file exposes broad generic HTTP and CRUD wrappers (add, edit, delete, http_post, http_put, http_get, http_delete) that can be used to contact arbitrary URLs and modify remote resources. For a skill whose declared purpose is limited to detecting strangers near minors and issuing alerts, this creates unnecessary capability expansion and increases the risk of misuse, data exfiltration, or unauthorized remote actions if higher-level inputs are attacker-controlled.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code supports remote resource creation, modification, and deletion through thin wrappers over HTTP POST/PUT/DELETE without any visible restriction tied to the skill’s safety-alert purpose. In the context of a child-safety monitoring skill, unjustified write/delete capability is especially risky because it could be repurposed to alter backend records, suppress alerts, or interact with unrelated services if abused.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file defines generic local user-account persistence unrelated to the declared purpose of detecting strangers near minors and issuing safety alerts. Capability mismatch is dangerous because it expands data collection and storage beyond user expectations, increasing privacy and abuse risk without a clear functional need in this skill context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The User model stores identity and authentication-related data such as real names, email, token, and open_token, which is not justified by a stranger-warning safety feature. In a child-safety context this is more sensitive because it may involve minors or guardians, so unnecessary credential and identity retention materially increases privacy and compromise impact.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code reads an internal identity from a local file, falls back to local database reuse, and automatically creates a persistent default open-id when none exists. For a child-safety alert skill, silent identity persistence is out of scope and dangerous because it enables durable tracking, backend correlation, and future authenticated activity without a clear user-driven setup flow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This utility layer performs user/account provisioning and login-related network flows that are unrelated to the declared stranger-warning function of the skill. In skill context, hidden identity bootstrap and remote account creation materially increase risk because the skill can initiate persistent backend access and transmit identifiers without user awareness.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises and instructs use of capabilities consistent with shell execution, local file handling, network access, and environment use, but it does not declare any explicit tool scope or permission boundaries. This creates an undeclared privilege surface where an agent may execute powerful operations without transparent limitation or review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill promotes surveillance, facial recognition, cloud history queries, and guardian notifications in a context involving minors, but it does not warn users about privacy-sensitive data collection, storage, sharing, retention, or consent requirements. Missing privacy disclosure in this setting is dangerous because operators may deploy invasive monitoring without understanding the legal and safety implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that uploaded attachments are automatically saved as local files but gives no user warning about local storage, retention, or who can access those files. Because the inputs may include surveillance images or videos of minors, silent local persistence increases privacy and leakage risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill requires historical reports to be fetched from a cloud API but does not clearly warn users that report data is retrieved from a remote service. In a high-sensitivity surveillance context, lack of remote-processing disclosure can conceal where sensitive records are stored and who may access them.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The only documentation in this file says this is a "Pet Analysis scripts package," which directly conflicts with the manifest describing a skill for detecting strangers near minors and issuing safety alerts. This is an intent-level contradiction in code documentation rather than a mere omission.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2