Back to skill

Security audit

Transpiration Rate Estimation | 室内绿植蒸腾速率估算

Security checks for vulnerabilities and agentic risk

Overview

This skill needs review because it sends user media to a cloud service while silently creating or reusing a local account identity, storing tokens, and containing leftover pet/video-analysis artifacts that do not fully match the plant-care purpose.

Install only if you are comfortable with a cloud service receiving the submitted plant images, videos, or URLs, and with the skill creating/reusing a local account identity and storing service tokens/report history locally. Avoid sensitive facility imagery until the publisher documents identity, token storage, retention, deletion, and the pet-analysis leftovers are cleaned up.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (64)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network access, identity generation/persistence, local workspace access, and database-backed user operations substantially exceed the implied behavior of a plant-care analysis skill. In context, this makes the mismatch more dangerous because the skill handles user-linked state and remote services while presenting itself as a benign scientific imaging utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network access, identity generation/persistence, local workspace access, and database-backed user operations substantially exceed the implied behavior of a plant-care analysis skill. In context, this makes the mismatch more dangerous because the skill handles user-linked state and remote services while presenting itself as a benign scientific imaging utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network access, identity generation/persistence, local workspace access, and database-backed user operations substantially exceed the implied behavior of a plant-care analysis skill. In context, this makes the mismatch more dangerous because the skill handles user-linked state and remote services while presenting itself as a benign scientific imaging utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network access, identity generation/persistence, local workspace access, and database-backed user operations substantially exceed the implied behavior of a plant-care analysis skill. In context, this makes the mismatch more dangerous because the skill handles user-linked state and remote services while presenting itself as a benign scientific imaging utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network access, identity generation/persistence, local workspace access, and database-backed user operations substantially exceed the implied behavior of a plant-care analysis skill. In context, this makes the mismatch more dangerous because the skill handles user-linked state and remote services while presenting itself as a benign scientific imaging utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network access, identity generation/persistence, local workspace access, and database-backed user operations substantially exceed the implied behavior of a plant-care analysis skill. In context, this makes the mismatch more dangerous because the skill handles user-linked state and remote services while presenting itself as a benign scientific imaging utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network access, identity generation/persistence, local workspace access, and database-backed user operations substantially exceed the implied behavior of a plant-care analysis skill. In context, this makes the mismatch more dangerous because the skill handles user-linked state and remote services while presenting itself as a benign scientific imaging utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network access, identity generation/persistence, local workspace access, and database-backed user operations substantially exceed the implied behavior of a plant-care analysis skill. In context, this makes the mismatch more dangerous because the skill handles user-linked state and remote services while presenting itself as a benign scientific imaging utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network access, identity generation/persistence, local workspace access, and database-backed user operations substantially exceed the implied behavior of a plant-care analysis skill. In context, this makes the mismatch more dangerous because the skill handles user-linked state and remote services while presenting itself as a benign scientific imaging utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network access, identity generation/persistence, local workspace access, and database-backed user operations substantially exceed the implied behavior of a plant-care analysis skill. In context, this makes the mismatch more dangerous because the skill handles user-linked state and remote services while presenting itself as a benign scientific imaging utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network access, identity generation/persistence, local workspace access, and database-backed user operations substantially exceed the implied behavior of a plant-care analysis skill. In context, this makes the mismatch more dangerous because the skill handles user-linked state and remote services while presenting itself as a benign scientific imaging utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network access, identity generation/persistence, local workspace access, and database-backed user operations substantially exceed the implied behavior of a plant-care analysis skill. In context, this makes the mismatch more dangerous because the skill handles user-linked state and remote services while presenting itself as a benign scientific imaging utility.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The metadata triggered a tool/manifest poisoning rule, and in context the file contains extensive behavior-shaping instructions that attempt to govern execution, history retrieval, local saving, and identity handling from within the manifest. Even if not overtly malicious, this kind of dense operational metadata can be used to smuggle undeclared capabilities or manipulate agent behavior beyond what the top-level description suggests.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-transpiration-rate-estimation-analysis"
description: "AI-powered transpiration rate estimation for indoor plants. From smart planters or fixed cameras, uses thermal infrared images of leaves (preferred) — or regular RGB images combined with ambient temperature/humidity — to estimate the leaf-to-air temperature difference, combines radiation/humidity parameters (sensor or model-inferred), and computes a relative transpiration rate index (0-100%). Transpiration rate correlates with root water-uptake activity, indirectly reflecting root health and water transport capacity. Helps determine whether the plant is water-stressed, has da

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file documents pet health analysis APIs inside a skill whose stated purpose is plant transpiration estimation, indicating a strong domain mismatch. This can cause the agent or downstream tooling to call unrelated endpoints, leak data to the wrong service, or expose unintended capabilities through confused-deputy behavior and misrouting.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The implementation does not match the declared skill purpose. Instead of plant transpiration estimation from imagery/sensor data, the file exposes a generic video-analysis wrapper that forwards user-provided input to another analysis backend, creating a significant integrity and trust problem because users may submit sensitive plant/facility imagery under false expectations. In a smart planter/greenhouse context, this mismatch can also mask broader data-handling behavior and make review of downstream processing difficult.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file implements generic user-account persistence, lookups, and default-user selection even though the declared skill is plant transpiration analysis. This scope mismatch is dangerous because it introduces identity and account-handling capabilities unrelated to the manifest, increasing the chance of covert data collection, retention of personal data, and abuse of shared infrastructure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The User model stores token and open_token fields despite the skill being for indoor plant transpiration estimation, and the generic DAO update methods can modify them. Storing authentication tokens without a clearly justified purpose creates a serious credential-handling risk: tokens may be persisted insecurely in local SQLite, exposed via backups or logs, or abused by adjacent code paths.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The utility performs automatic account bootstrap, token retrieval, and persistent local user creation even though the declared skill purpose is plant transpiration analysis. This creates hidden identity and account side effects, sends identifiers to remote services, and expands the skill's privileges well beyond what a user would reasonably expect from an image-analysis function.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares broad operational behavior including shell execution, network access, local file save/read, and environment-backed identity handling, but does not declare any explicit tool scope or permissions boundaries. This creates an opaque trust boundary where a caller cannot easily understand or constrain what capabilities the skill may use, increasing the chance of unintended file, network, or command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The history-report trigger phrases are broad enough that ordinary requests like asking for historical reports could unintentionally invoke account-linked cloud history retrieval. In this skill, that is risky because history access is tied to internal identity resolution and remote APIs, so accidental triggering could disclose prior report metadata without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that uploaded attachments are automatically saved as local files but does not provide a clear user-facing warning about this persistence. Automatic local storage increases privacy and integrity risk because sensitive media may remain on disk beyond the immediate task, contrary to user expectations for a simple analysis workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill allows users to provide network URLs and notes that an external API service will fetch them, but it lacks a strong privacy/integrity warning about that transfer. This is dangerous because user-supplied URLs and referenced content may be disclosed to third-party infrastructure, and fetched remote content may not match the user’s assumptions about where processing occurs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The main analysis entrypoint is named analyze_video and accepts pet_type, while the manifest describes estimating plant transpiration from leaf thermal/RGB imagery. This mismatch is reinforced by later CLI messaging and suggests the code's documented intent contradicts the declared plant-analysis purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The argument parser description and multiple help strings are hard-coded in Chinese, and the runtime status/error messages are also Chinese-only. This imposes a specific language on users without any opt-in, fallback, or documented region-specific justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI exposes --pet-type choices of cat, dog, and other, even though the surrounding help and manifest claim the tool estimates indoor plant transpiration. This is a direct contradiction between the code's visible interface semantics and its claimed intent.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2