Back to skill

Security audit

Ezviz Open Capture Phone Detect

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated camera phone-detection purpose, but it handles surveillance images and device playback while shipping realistic credential examples and a duplicate alert path that warrant manual review.

Review before installing. Use only with explicit authorization for the monitored area, create restricted Ezviz credentials limited to the required APIs/devices, rotate any exposed-looking sample credentials if they were ever real, and remove or patch the duplicate alert block and undisclosed fallback downloads before production use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Warning
Location
references/ezviz-api-docs.md:54
Finding

Credential-Shaped Secrets Embedded in API Documentation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/phone_detection_alert.py:655
Finding

Duplicate Alert Workflow and Full Signed Voice URL Logging

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/phone_detection_alert.py:305
Finding

Predictable Files in a Shared Temporary Directory

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:26
Finding

Unpinned Runtime Dependencies

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/phone_detection_alert.py:345
Finding

Undeclared and Unvalidated Audio Download from an Unrelated Domain

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (22)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/phone_detection_alert.py (reported line 50)May include surrounding context.

python
def get_access_token(app_key, app_secret):
    """
    Get access token using appKey and appSecret.
    
    API: POST /api/lapp/token/get
    Content-Type: application/x-www-form-urlencoded

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/phone_detection_alert.py (reported line 62)May include surrounding context.

python
def get_access_token(app_key, app_secret):
    """
    Get access token using appKey and appSecret.
    
    API: POST /api/lapp/token/get
    Content-Type: application/x-www-form-urlencoded

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/phone_detection_alert.py (reported line 119)May include surrounding context.

python
def get_access_token(app_key, app_secret):
    """
    Get access token using appKey and appSecret.
    
    API: POST /api/lapp/token/get
    Content-Type: application/x-www-form-urlencoded

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/phone_detection_alert.py (reported line 200)May include surrounding context.

python
def get_access_token(app_key, app_secret):
    """
    Get access token using appKey and appSecret.
    
    API: POST /api/lapp/token/get
    Content-Type: application/x-www-form-urlencoded

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/phone_detection_alert.py (reported line 447)May include surrounding context.

python
def get_access_token(app_key, app_secret):
    """
    Get access token using appKey and appSecret.
    
    API: POST /api/lapp/token/get
    Content-Type: application/x-www-form-urlencoded

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/phone_detection_alert.py (reported line 544)May include surrounding context.

python
def get_access_token(app_key, app_secret):
    """
    Get access token using appKey and appSecret.
    
    API: POST /api/lapp/token/get
    Content-Type: application/x-www-form-urlencoded

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/phone_detection_alert.py (reported line 571)May include surrounding context.

python
def get_access_token(app_key, app_secret):
    """
    Get access token using appKey and appSecret.
    
    API: POST /api/lapp/token/get
    Content-Type: application/x-www-form-urlencoded

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file consistently presents its operational description, setup guidance, warnings, and outputs in Chinese, which effectively imposes a specific language on users. The policy allows locale constraints only when clearly justified or when users are given a language choice, neither of which is present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document outlines a pipeline that captures live camera images, analyzes human behavior, uploads audio, and pushes voice playback to a device. For markdown files, these are user-data, privacy, and system-impacting behaviors that should be accompanied by an explicit warning so operators understand the monitoring and device-control implications before use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document includes live-looking app credentials and access tokens in example requests without any warning that these values must be treated as secrets. Even if intended as samples, realistic-looking secrets are often copied, tested, or accidentally left valid, which can lead to unauthorized API access, token reuse, account abuse, or downstream compromise of connected surveillance devices and data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/ezviz-api-docs.md (reported line 226)May include surrounding context.

请求示例

bash
curl --location --request POST 'https://open.ys7.com/api/service/intelligence/algo/analysis/play_phone_detection' \
  --header 'accessToken: at.3xwsj8em6p28dw3t92nf4itq4mote8qr-6t75j5aq2m-1i7rkyf-pwz8z7rfi' \
  --header 'Content-Type: application/json' \
  --data-raw '{

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring says the workflow starts by capturing a camera snapshot and then performing detection, implying direct camera-based acquisition. In practice, main() calls get_access_token() and capture_device_image() to remotely capture images from Ezviz devices using the vendor cloud API, and the local capture_snapshot() path is never used.

Content

No source excerpt is available for this finding.

Tainted flow: 'data' from requests.post (line 85, network input) → requests.post (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/phone_detection_alert.py (reported line 139)May include surrounding context.

python
}
    
    try:
        response = requests.post(
            DEVICE_CAPTURE_API_URL,
            headers=headers,
            data=data,

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The script sends image URLs representing surveillance snapshots to an external analysis service. Even though this is core functionality, it is still a real external transmission of potentially sensitive visual data and is dangerous if deployed without clear authorization, privacy controls, and data-governance review.

Content

Scanner excerpt · scripts/phone_detection_alert.py (reported line 233)May include surrounding context.

python
}
    
    try:
        response = requests.post(
            PHONE_DETECTION_API_URL,
            headers=headers,
            json=payload,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script transmits captured surveillance images to an external phone-detection cloud API without any explicit notice, consent gate, or configurable privacy control. Because the data may contain people and sensitive scenes, silent third-party transmission increases privacy, compliance, and data-handling risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The TTS voice is fixed to zh-CN-XiaoxiaoNeural and the fallback gTTS language is fixed to zh-cn, forcing a specific locale. This is a natural-language policy issue because the skill does not offer any language selection, opt-in, or documented justification for enforcing Chinese output.

Content

No source excerpt is available for this finding.

Tainted flow: 'data' from requests.post (line 413, network input) → requests.post (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/phone_detection_alert.py (reported line 401)May include surrounding context.

python
data = {
                'voiceName': voice_name
            }
            response = requests.post(
                VOICE_UPLOAD_API_URL,
                params=params,
                files=files,

Tainted flow: 'data' from requests.post (line 413, network input) → requests.post (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/phone_detection_alert.py (reported line 464)May include surrounding context.

python
}
    
    try:
        response = requests.post(
            VOICE_SEND_API_URL,
            headers=headers,
            data=data,

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

After processing all devices, the code reuses the last detection_result/device_serial in a duplicated alert block, which can trigger a second unintended upload/send operation. In a security/automation context, duplicated actions against surveillance devices can cause unauthorized repeated playback, operator confusion, and actions on the wrong target device.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The spoken alert message is fixed as Chinese text, which enforces a specific language for end users and device recipients. The file provides no mechanism for selecting another language or confirming that Chinese is desired.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The step descriptions say '调用接口 1/2/3' for phone detection, voice upload, and voice send, but in this document those capabilities are actually documented as sections 2, 3, and 4 respectively. This is an active documentation contradiction that could cause implementers to call the wrong APIs in a security-sensitive workflow involving image analysis and device voice playback.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

Alert text is sent to third-party TTS services (edge-tts or gTTS) without a clear privacy notice or consent path. While the current fixed text is not highly sensitive, the function accepts arbitrary text and could expose sensitive operational content if reused.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/ezviz-api-docs.md:138