Back to skill

Security audit

Emocity Biometric Scan

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed biometric and mood-scanning integration, but users should treat it as sensitive and only scan people who consent.

Install only if you are comfortable using a hosted biometric/emotional-analysis service. Use it only on yourself or on people who clearly agreed, do not treat stress, mood, genuineness, or deception scores as medical or truthfulness determinations, and remember that optional photo or video API analysis uploads the selected file to EmoPulse through RapidAPI using your own key.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README prominently markets biometric and affective inference features, while the privacy warning appears later and is comparatively understated. Because this skill processes highly sensitive face, voice, stress, mood, and deception-related data and also references anonymous analytics and summary score transmission, users may engage before understanding the privacy implications and downstream data sharing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill encourages judgments about stress, mood, genuineness, and a 'deception challenge' without presenting strong limitations or explicit opt-in at the point of use. These outputs can be misused to make sensitive interpersonal or quasi-medical judgments about a person’s honesty or emotional state, especially in social or coercive contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage conditions authorize the skill for broad requests like any "face scan" or "stress or heart-rate check from the camera," which are common natural-language intents that may overlap with other tools or general assistant behavior. In this context, ambiguous routing is more dangerous because the skill handles highly sensitive biometric, affective, and potentially voice-derived data, so accidental invocation can lead users into privacy-invasive analysis they did not specifically intend to use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger examples include short, generic phrases like "Check my stress" that could cause the platform to invoke this skill for broad health- or camera-related requests without an explicit product name. Because this skill processes sensitive biometric and emotional inferences, overly broad invocation language increases the risk of accidental activation and inappropriate routing of users into a face/audio analysis workflow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest identity conflicts with the presented skill context: the file is being reviewed as 'emocity-biometric-scan' while the manifest declares 'fitcheck-workout-readiness' and a different display name. In a skill that requests highly sensitive biometric inputs such as camera, microphone, and uploaded media, this mismatch can mislead users, reviewers, or deployment tooling about what is actually being installed, weakening consent and trust boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The description specifies a fixed analysis flow and outputs interpretations such as mood, micro-expressions, eye contact, and voice tension, but provides no indication that language or locale can be selected or adjusted. Because SQP-3 covers natural-language policy issues across all file types, the absence of any user opt-in or locale choice for potentially language-sensitive voice analysis is a policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.