Back to skill

Security audit

Turtle Pneumonia Symptom (Open-Mouth Breathing) Detection | 龟类张嘴呼吸(肺炎征兆)识别

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a cloud-backed turtle video analysis client, but it silently creates and reuses persistent user identity and authentication tokens for report history, which needs user review before installation.

Install only if you are comfortable with turtle images/videos and report history being processed by the configured LifeEmergence cloud service and tied to a persistent local identity. Review or isolate the workspace data directory before use, avoid sensitive camera footage unless the provider's retention and deletion practices are acceptable, and treat generated reports as visual risk warnings rather than veterinary diagnosis.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (59)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, auth/token management, user identity generation/persistence, workspace discovery, and local database interaction together represent a much broader system than a simple symptom-detection skill. The combination materially increases the risk of privacy leakage, unauthorized access to user-linked records, and stealthy data collection under a misleading description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, auth/token management, user identity generation/persistence, workspace discovery, and local database interaction together represent a much broader system than a simple symptom-detection skill. The combination materially increases the risk of privacy leakage, unauthorized access to user-linked records, and stealthy data collection under a misleading description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, auth/token management, user identity generation/persistence, workspace discovery, and local database interaction together represent a much broader system than a simple symptom-detection skill. The combination materially increases the risk of privacy leakage, unauthorized access to user-linked records, and stealthy data collection under a misleading description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, auth/token management, user identity generation/persistence, workspace discovery, and local database interaction together represent a much broader system than a simple symptom-detection skill. The combination materially increases the risk of privacy leakage, unauthorized access to user-linked records, and stealthy data collection under a misleading description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, auth/token management, user identity generation/persistence, workspace discovery, and local database interaction together represent a much broader system than a simple symptom-detection skill. The combination materially increases the risk of privacy leakage, unauthorized access to user-linked records, and stealthy data collection under a misleading description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, auth/token management, user identity generation/persistence, workspace discovery, and local database interaction together represent a much broader system than a simple symptom-detection skill. The combination materially increases the risk of privacy leakage, unauthorized access to user-linked records, and stealthy data collection under a misleading description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, auth/token management, user identity generation/persistence, workspace discovery, and local database interaction together represent a much broader system than a simple symptom-detection skill. The combination materially increases the risk of privacy leakage, unauthorized access to user-linked records, and stealthy data collection under a misleading description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, auth/token management, user identity generation/persistence, workspace discovery, and local database interaction together represent a much broader system than a simple symptom-detection skill. The combination materially increases the risk of privacy leakage, unauthorized access to user-linked records, and stealthy data collection under a misleading description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, auth/token management, user identity generation/persistence, workspace discovery, and local database interaction together represent a much broader system than a simple symptom-detection skill. The combination materially increases the risk of privacy leakage, unauthorized access to user-linked records, and stealthy data collection under a misleading description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, auth/token management, user identity generation/persistence, workspace discovery, and local database interaction together represent a much broader system than a simple symptom-detection skill. The combination materially increases the risk of privacy leakage, unauthorized access to user-linked records, and stealthy data collection under a misleading description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

External HTTP communication, auth/token management, user identity generation/persistence, workspace discovery, and local database interaction together represent a much broader system than a simple symptom-detection skill. The combination materially increases the risk of privacy leakage, unauthorized access to user-linked records, and stealthy data collection under a misleading description.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The metadata triggered a tool-poisoning style rule, likely due to suspicious manifest content or malformed/hidden characters near the description field. In skill manifests, metadata anomalies are risky because orchestrators often trust manifest fields for routing and safety decisions, so poisoned or obfuscated metadata can mislead downstream tooling and reviewers.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-turtle-pneumonia-symptom-detection-analysis"
description: "Through fixed enclosure cameras, the system analyzes mouth and nasal videos of turtles to detect abnormally frequent open-mouth breathing in non-feeding states (mouth opening frequency unusually elevated), as well as the presence of mucus (reflective spots or strands) or nasal discharge around the mouth and nose. | 通过龟缸固定摄像头,分析龟类的口鼻部视频,检测龟在非进食状态下(未摄食时)口部频繁开合(张嘴呼吸,频率异常增高),以及口鼻区域是否有黏液(反光点或丝状物)或鼻腔分泌物。当同时或单�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file defines persistent user-account storage and lookup behavior that is unrelated to the manifest's turtle pneumonia video-analysis purpose. In a least-privilege review, unexplained user identity handling materially increases attack surface, enables unnecessary collection of personal data, and may support hidden tracking or account linkage beyond the declared function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The model stores username, real name, email, token, and open_token fields, which are highly sensitive and unjustified for a turtle symptom detection capability. Unnecessary handling of identity and authentication-like data expands privacy, credential exposure, and misuse risks, especially since the manifest gives no indication that user accounts or tokens are needed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility file contains broad identity resolution, local user creation, token handling, database persistence, workspace discovery, and outbound service access that are unrelated to a turtle pneumonia video-analysis skill. Such hidden cross-cutting capabilities expand the attack surface and enable unintended data access and remote account operations far beyond the declared purpose of symptom detection.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code can auto-login or auto-register users against remote health endpoints, derive an identity, receive tokens, and store them locally. For a turtle-camera diagnostic skill, this is unjustified and dangerous because it silently turns local skill execution into remote account enrollment and credential handling.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares no explicit tool scope or permission boundaries even though the surrounding behavior indicates access to shell, filesystem, environment variables, and network. In an agent setting, missing least-privilege declarations increases the chance that the skill can perform unintended local or remote actions without transparent user consent or runtime restriction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The history-report trigger phrases are broad enough that ordinary user wording could automatically invoke cloud history retrieval without clear intent. In a health-related context, unintended retrieval of prior reports can expose sensitive records and surprise users who only meant to ask a general question.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states that uploaded attachments are automatically saved locally but does not clearly warn users up front about this storage behavior. Silent local persistence of user media, especially health-related video, creates avoidable privacy and retention risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill omits a clear warning that user-provided media URLs/files may be sent to a cloud API for analysis or history lookup. Sending animal-health videos and associated metadata to external services without explicit disclosure and consent is a significant privacy and trust issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The method returns a fixed Chinese-language heading string, with no indication that the user can choose another language or locale. This can violate language/locale policy when the skill is used in broader contexts where users have not opted into Chinese output.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script exposes a --list mode that retrieves historical analysis records via skill.get_output_analysis_list(open_id=open_id), which is outside the stated symptom-detection purpose in the manifest. Hidden or undocumented data-access functionality increases the chance of unauthorized record enumeration or privacy violations, especially because it is tied to an internal identity mechanism rather than explicit user-scoped authorization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code hardcodes the command description, argument help text, and status/error messages in Chinese. The policy for natural-language behavior applies to all file types, and there is no indication that the user can choose a language or that the locale restriction is documented as region-specific and justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill resolves and uses an internal open_id even though the advertised function is local/video symptom analysis. Introducing hidden identity initialization and then using that identity to fetch history creates an unnecessary data-linkage surface that could expose user-associated records or enable cross-user access if open_id resolution is weak or spoofable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file uses only Chinese-language headings and descriptions, which can impose a fixed language choice on users without opt-in. Under the policy, forcing a specific language without offering a choice or documenting a justified regional limitation is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2