Back to skill

Security audit

Ezviz Open Multimodal Analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it handles camera credentials and images in ways that can expose sensitive tokens or signed camera-image URLs.

Review before installing. Use a dedicated least-privilege Ezviz application, avoid passing AppSecret on the command line, prefer protected environment or secret-manager configuration, set EZVIZ_TOKEN_CACHE=0 on shared systems, and do not run the cron example without first removing signed image URLs from normal output and logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/multimodal_analysis.py:322
Finding

Signed Camera Image URLs Are Exposed in Console and Scheduled-Task Logs

Content
View full analysis
=4s interval) time.sleep(4) # Summary print(f"\n{'='*70}") print("ANALYSIS SUMMARY") print(f"{'='*70}") print(f" Total devices: {results['total']}") print(f" Success: {results['success']}") print(f" Failed: {results['failed']}") print(f"{'='*70}") print(f"\n[JSON Result]") print(json.dumps(results, indent=2, ensure_ascii=False)) ``` ### Technical Analysis The program initially displays only a truncated image URL, but then stores the complete URL in the result object and prints that object as JSON. The URL returned by the camera capture API is a signed URL that can provide temporary access to a surveillance image. The project documentation states that these URLs remai ...[truncated 1706 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
lib/token_manager.py:44
Finding

Access Tokens Are Stored Through Predictable and Insufficiently Protected Temporary Paths

Content
View full analysis
/ezviz_global_token_cache` - Temporary file: `global_token_cache.json.tmp` - Final file: `global_token_cache.json` The implementation creates the directory without explicitly setting mode `0700` and does not verify that the directory is owned by the current user or that it is not a symbolic link. It then opens a predictable temporary file using the process umask and applies mode `0600` only after the file has been written and renamed. The final `chmod(0600)` does not protect the credential during its initial write. On a shared system, an attacker may pre-create the predictable directory with permissive permissions, monitor the temporary file, interfere with the path, or exploit symbolic-link behavior. The cache contains live Ezviz access tokens and identifying AppKey prefixes. Although atomic replacement reduces partial-write risks, it does not make predictable temporary-file creation safe. The implementation also lacks file locking, so concurrent Skill processes can overwrite each other's cache updates. ### Attack Path ...[truncated 1546 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/multimodal_analysis.py:203
Finding

Ezviz AppSecret Can Be Supplied Through Process Command-Line Arguments

Content
View full analysis
1 else "" app_secret = APP_SECRET or sys.argv[2] if len(sys.argv) > 2 else "" ``` The corresponding usage is explicitly documented as: ```bash python3 {baseDir}/scripts/multimodal_analysis.py appKey appSecret dev1 1 agentId ``` ### Technical Analysis The Skill accepts the Ezviz AppSecret as a positional command-line argument. Command-line arguments are not an appropriate secret-transport mechanism because they may be exposed through: - Process inspection tools such as `ps` - `/proc//cmdline` on applicable systems - Shell history - Job schedulers and process supervisors - Audit and endpoint-monitoring products - Diagnostic bundles and crash reports - Terminal session recording This exposure is avoidable because the Skill already supports environment variables and configuration files. Accepting the secret through `argv` expands the number of processes and users that may observe a long-lived credential. The AppSecret is more sensitive than the cached access token because it can generally be used to request new access tokens repeatedly until the credential is revoked or rotated. ### Attack Path 1. An operator follows the documented command-line usage and places the AppKey and AppSecret directly in the command. 2. The shell stores the command in history, or the operating system exposes it in the process argument list while the Skill runs. 3. A local user, monitoring agent, scheduler administrator, or compromised process-inspection component records the argument. 4. The attacker extracts the AppSecret. 5. The attacker submits the AppKey and AppSecret to the Ezviz token endpoint. 6. The attacker obtains access tokens and invokes APIs permitted to that Ezvi ...[truncated 656 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (36)

Tainted flow: 'payload' from os.environ.get (line 184, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/multimodal_analysis.py (reported line 193)May include surrounding context.

python
}
    
    try:
        response = requests.post(AGENT_ANALYSIS_API_URL, headers=headers, json=payload, timeout=60)
        result = response.json()
        
        # Don't log full response to avoid leaking data

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The metadata says EZVIZ_APP_KEY and EZVIZ_APP_SECRET must be set as environment variables, but the skill can also source credentials from local config files and command-line arguments. This mismatch undermines the stated security requirement, may cause unintended credential ingestion from disk, and broadens the ways secrets can be introduced and exposed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The metadata says EZVIZ_APP_KEY and EZVIZ_APP_SECRET must be set as environment variables, but the skill can also source credentials from local config files and command-line arguments. This mismatch undermines the stated security requirement, may cause unintended credential ingestion from disk, and broadens the ways secrets can be introduced and exposed.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 606)May include surrounding context.

cat /tmp/ezviz_global_token_cache/global_token_cache.json

清除缓存

rm -rf /tmp/ezviz_global_token_cache/

text

### 验证命令

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 663)May include surrounding context.

cat /tmp/ezviz_global_token_cache/global_token_cache.json

清除缓存

rm -rf /tmp/ezviz_global_token_cache/

text

### 验证命令

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 606)May include surrounding context.

cat /tmp/ezviz_global_token_cache/global_token_cache.json

清除缓存

rm -rf /tmp/ezviz_global_token_cache/

text

### 验证命令

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 663)May include surrounding context.

cat /tmp/ezviz_global_token_cache/global_token_cache.json

清除缓存

rm -rf /tmp/ezviz_global_token_cache/

text

### 验证命令

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 641)May include surrounding context.

2. 环境变量安全

bash
# 推荐:使用 .env 文件(不要提交到版本控制)
echo "EZVIZ_APP_KEY=your_key" >> .env
echo "EZVIZ_APP_SECRET=your_secret" >> .env
chmod 600 .env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 642)May include surrounding context.

2. 环境变量安全

bash
# 推荐:使用 .env 文件(不要提交到版本控制)
echo "EZVIZ_APP_KEY=your_key" >> .env
echo "EZVIZ_APP_SECRET=your_secret" >> .env
chmod 600 .env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 643)May include surrounding context.

2. 环境变量安全

bash
# 推荐:使用 .env 文件(不要提交到版本控制)
echo "EZVIZ_APP_KEY=your_key" >> .env
echo "EZVIZ_APP_SECRET=your_secret" >> .env
chmod 600 .env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 644)May include surrounding context.

2. 环境变量安全

bash
# 推荐:使用 .env 文件(不要提交到版本控制)
echo "EZVIZ_APP_KEY=your_key" >> .env
echo "EZVIZ_APP_SECRET=your_secret" >> .env
chmod 600 .env

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

The example instructs users to 'source .env', which imports the file into the current shell and may execute arbitrary shell content if the file is modified or maliciously crafted. In environments where .env contents are not tightly controlled, this creates a command-execution risk beyond simple variable loading.

Content

Scanner excerpt · SKILL.md (reported line 647)May include surrounding context.

chmod 600 .env

加载环境变量

source .env

text

### 3. 禁用缓存(高安全场景)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 271)May include surrounding context.

md
def get_cached_token(app_key, app_secret, use_cache=None):
    """
    Get access token, using cached version if available and valid.
    
    Args:
        app_key: Ezviz app key

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 622)May include surrounding context.

md
def get_cached_token(app_key, app_secret, use_cache=None):
    """
    Get access token, using cached version if available and valid.
    
    Args:
        app_key: Ezviz app key

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/token_manager.py (reported line 120)May include surrounding context.

python
def get_cached_token(app_key, app_secret, use_cache=None):
    """
    Get access token, using cached version if available and valid.
    
    Args:
        app_key: Ezviz app key

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/token_manager.py (reported line 173)May include surrounding context.

python
def get_cached_token(app_key, app_secret, use_cache=None):
    """
    Get access token, using cached version if available and valid.
    
    Args:
        app_key: Ezviz app key

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/token_manager.py (reported line 189)May include surrounding context.

python
def get_cached_token(app_key, app_secret, use_cache=None):
    """
    Get access token, using cached version if available and valid.
    
    Args:
        app_key: Ezviz app key

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/multimodal_analysis.py (reported line 169)May include surrounding context.

python
def get_cached_token(app_key, app_secret, use_cache=None):
    """
    Get access token, using cached version if available and valid.
    
    Args:
        app_key: Ezviz app key

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/multimodal_analysis.py (reported line 276)May include surrounding context.

python
def get_cached_token(app_key, app_secret, use_cache=None):
    """
    Get access token, using cached version if available and valid.
    
    Args:
        app_key: Ezviz app key

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/multimodal_analysis.py (reported line 278)May include surrounding context.

python
def get_cached_token(app_key, app_secret, use_cache=None):
    """
    Get access token, using cached version if available and valid.
    
    Args:
        app_key: Ezviz app key

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The CLI prints the first 30 characters of the access token to stdout. Even partial token disclosure is dangerous because terminals, shell history wrappers, CI logs, support captures, or observability systems may retain the output, and bearer tokens often must be treated as fully secret.

Content

Scanner excerpt · lib/token_manager.py (reported line 361)May include surrounding context.

python
result = get_cached_token(args.app_key, args.app_secret, use_cache=use_cache)
        
        if result["success"]:
            print(f"\nAccess Token: {result['access_token'][:30]}...")
            print(f"Expires: {time.strftime('%Y-%m-%d %H:%M:%S', time.localtime(result['expire_time'] / 1000))}")
            print(f"From Cache: {result['from_cache']}")
        else:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents capabilities including environment-variable access, reading local config files, writing a token cache, network calls, and shell-style operational commands, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege enforcement and makes it harder for a host agent to constrain file, network, and shell access appropriately.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description and invocation guidance are written as Chinese-only operational instructions, including the 'Use when' clause, with no indication that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 644)May include surrounding context.

md
# 推荐:使用 .env 文件(不要提交到版本控制)
echo "EZVIZ_APP_KEY=your_key" >> .env
echo "EZVIZ_APP_SECRET=your_secret" >> .env
chmod 600 .env

# 加载环境变量
source .env

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code persists access tokens to a global cache file in the system temporary directory, which affects sensitive user credentials at rest. While the module has internal comments and logging about cache behavior, there is no user-facing warning or disclosure near the CLI or API entry points that tokens will be stored locally on disk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/ezviz-agent-api.md:108