Back to skill

Security audit

Autism Spectrum Disorder Behavior Analysis Tool | 孤独症谱系障碍行为分析工具

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-related but needs Review because it handles children's health videos with under-disclosed cloud upload, automatic identity/account handling, local token storage, and insecure HTTP endpoints.

Review carefully before installing. Do not use real child videos or identifiable health-related media unless the publisher documents who receives the data, retention/deletion terms, HTTPS-only transport, token protection, and explicit consent/authorization for history lookup and account creation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/util.py:548
Finding

Sensitive Child Health Data and Authentication Tokens Transmitted Over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Locations:

  • skills/smyx_common/scripts/config.yaml:15
  • skills/smyx_common/scripts/config-dev.yaml:2-4
  • skills/smyx_common/scripts/util.py:548-561
  • skills/smyx_common/scripts/util.py:572-646
  • skills/smyx_analysis/scripts/skill.py:113-139

Vulnerability Type: Plaintext transmission of sensitive medical media, identity data, and authentication credentials
Risk Level: High

Vulnerable Code

The packaged configuration activates the development environment:

yaml
env: dev

That environment replaces the nominal HTTPS API services with plaintext HTTP endpoints:

yaml
ApiEnum:
  base-url-open-api: "http://192.168.1.234:9601/smyx-open-api"
  base-url-open-h5: "http://192.168.1.234:4100"
  base-url-health: "http://192.168.1.234:7070/jeecg-boot-xzgz"

Automatic account creation sends the resolved internal identifier in both the openId and mobile fields:

python
def _get_or_create_user(username):
    _url = ApiEnum.BASE_URL_HEALTH + "/sys/phoneLogin"
    open_id = username
    _data = {
        "silent": 1,
        "register": 1,
        "openId": open_id,
        "mobile": username,
        "source": ConstantEnum.DEFAULT__SKILL_HUB_NAME
    }
    try:
        _response = requests.post(_url, json=_data)
        if _response.status_code == 200:
            _response_json = _response.json()
            if _response_json and _response_json.get("success"):
                return _response_json and _response_json.get("result")
    except Exception as _e:
        CommonUtil.trace_exception_stack(_e)
    return {}

The common request layer attaches authentication tokens and identity metadata to outgoing requests. It also permits request data to be moved into URL parameters:

python
if not url.startswith("https://") and not url.startswith("http://"):
    url = cls.BASE_URL + url

headers['App-Id'] = ConstantEnum.APP__ID

headers.setdefault("X-Access-Token", ApiEnum.TOKEN)
headers.setdefault("X-A
...[truncated 5627 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require HTTPS for every service endpoint

    • Reject URLs that do not begin with https://.
    • Do not permit plaintext HTTP as a silent fallback.
    • Fail closed with a clear security error if an insecure endpoint is configured.
  2. Ship production-safe configuration

    • Remove env: dev from release artifacts or change it to a production environment that uses HTTPS exclusively.
    • Keep private development endpoints in a separate, unshipped configuration.
    • Add startup validation that prevents development configuration from being used in production.
  3. Maintain certificate validation

    • Keep TLS certificate verification enabled.
    • Do not introduce verify=False.
    • Where appropriate, restrict trusted certificate authorities or use certificate pinning for high-sensitivity health-data endpoints.
  4. Keep sensitive data out of URLs

    • Remove dataAsParams for requests containing identity, health, tenant, or authentication information.
    • Transmit necessary fields in an encrypted request body.
    • Ensure tokens are sent only in headers over HTTPS.
  5. Minimize identity collection

    • Do not duplicate the same identifier as openId, mobile, and pnaUserName.
    • Do not label a generated internal identifier as a mobile number.
    • Send only the minimum pseudonymous identifier required by the server.
  6. Protect child health media

    • Obtain explicit informed consent before uploading child video.
    • Clearly disclose the service operator, destination, retention period, deletion process, and whether media is used for model training.
    • Provide a deletion mechanism for uploaded media and generated reports.
    • Avoid retaining media locally longer than necessary.
  7. Protect and rotate credentials

    • Rotate any tokens that may have been transmitted through the HTTP development endpoints.
    • Store tokens using operating-system credential storage or an encrypted secret store rat ...[truncated 668 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The implementation reportedly performs authenticated HTTP requests, local file and directory operations, workspace detection, identity resolution, and token persistence, none of which are clearly disclosed by the autism-analysis description. In a pediatric health-related context, this is dangerous because it combines sensitive content handling with hidden credential, token, and storage behaviors that could expose private videos, reports, or account data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The implementation reportedly performs authenticated HTTP requests, local file and directory operations, workspace detection, identity resolution, and token persistence, none of which are clearly disclosed by the autism-analysis description. In a pediatric health-related context, this is dangerous because it combines sensitive content handling with hidden credential, token, and storage behaviors that could expose private videos, reports, or account data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The implementation reportedly performs authenticated HTTP requests, local file and directory operations, workspace detection, identity resolution, and token persistence, none of which are clearly disclosed by the autism-analysis description. In a pediatric health-related context, this is dangerous because it combines sensitive content handling with hidden credential, token, and storage behaviors that could expose private videos, reports, or account data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The implementation reportedly performs authenticated HTTP requests, local file and directory operations, workspace detection, identity resolution, and token persistence, none of which are clearly disclosed by the autism-analysis description. In a pediatric health-related context, this is dangerous because it combines sensitive content handling with hidden credential, token, and storage behaviors that could expose private videos, reports, or account data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The implementation reportedly performs authenticated HTTP requests, local file and directory operations, workspace detection, identity resolution, and token persistence, none of which are clearly disclosed by the autism-analysis description. In a pediatric health-related context, this is dangerous because it combines sensitive content handling with hidden credential, token, and storage behaviors that could expose private videos, reports, or account data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The implementation reportedly performs authenticated HTTP requests, local file and directory operations, workspace detection, identity resolution, and token persistence, none of which are clearly disclosed by the autism-analysis description. In a pediatric health-related context, this is dangerous because it combines sensitive content handling with hidden credential, token, and storage behaviors that could expose private videos, reports, or account data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The implementation reportedly performs authenticated HTTP requests, local file and directory operations, workspace detection, identity resolution, and token persistence, none of which are clearly disclosed by the autism-analysis description. In a pediatric health-related context, this is dangerous because it combines sensitive content handling with hidden credential, token, and storage behaviors that could expose private videos, reports, or account data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The implementation reportedly performs authenticated HTTP requests, local file and directory operations, workspace detection, identity resolution, and token persistence, none of which are clearly disclosed by the autism-analysis description. In a pediatric health-related context, this is dangerous because it combines sensitive content handling with hidden credential, token, and storage behaviors that could expose private videos, reports, or account data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The implementation reportedly performs authenticated HTTP requests, local file and directory operations, workspace detection, identity resolution, and token persistence, none of which are clearly disclosed by the autism-analysis description. In a pediatric health-related context, this is dangerous because it combines sensitive content handling with hidden credential, token, and storage behaviors that could expose private videos, reports, or account data.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "autism-analysis"
description: "Performs special video analysis on behavioral characteristics of children with autism, identifies core symptom features, provides structured analysis reports and intervention recommendations. | 孤独症谱系障碍行为分析工具,针对儿童孤独症行为特征进行专项视频分析,识别核心症状特征,提供结构化分析报告和干预建议"
version: "1.0.14"
license: "MIT-0"
---

# 🧩 Autism Spectrum Disorder Behavior Analysis Tool | 孤独症谱系障碍行为分析工具

> **智能健康/识别分析中枢** · 图片/视频智能分析 · 结构化�

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill solicits or expects child image/video uploads for autism-related analysis but does not clearly warn users that this sensitive media may be transmitted to cloud services. Given the subject matter involves children and health-related behavioral assessment, omission of a prominent cloud-transmission disclosure undermines informed consent and can lead to serious privacy, legal, and compliance risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This service exposes broad generic network and CRUD capabilities, including arbitrary URL-based GET/POST/PUT/DELETE wrappers, that are not narrowly scoped to the stated purpose of autism-related video behavior analysis. In an agent skill context, unnecessary general-purpose HTTP primitives materially expand the attack surface and can enable unintended data exfiltration, unauthorized backend access, or use of the skill as a proxy to interact with unrelated systems.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file defines a generic user/account DAO inside a skill described as autism behavioral video analysis, which is a strong scope mismatch. In a sensitive healthcare-adjacent context, unrelated identity storage increases the chance of hidden data collection, unnecessary account linkage, and abuse of personal information outside the stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The User model stores token, open_token, email, birthday, realname, and other profile data without any demonstrated need tied to autism video analysis. In a child-focused health-related skill, collecting and retaining authentication tokens and personal data is especially risky because it expands privacy impact and potential account compromise if the local/shared database is accessed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code can read an identity from a workspace file, fall back to a local database, and generate and persist synthetic default users automatically. This is unrelated to autism analysis and dangerous because it silently establishes durable identities that can be used for authenticated actions and external service access without informed user approval.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The utility layer implements token management, user lookup, silent registration/login, and authenticated API bootstrapping that are unrelated to autism video analysis. This creates hidden account and credential workflows that expand the skill's privileges and allow undisclosed interaction with remote services under generated or recovered identities.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises capabilities that imply shell, file, environment, and network access but does not declare any explicit tool scope or permissions boundary. This weakens least-privilege controls and makes it harder for a host system or reviewer to determine what the skill is actually allowed to do, increasing the risk of unintended command execution, file access, or data exfiltration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The history-report trigger phrases are broad enough that ordinary user language may unintentionally invoke report-listing behavior. In this skill, that is more dangerous than usual because historical reports concern sensitive child developmental and health-adjacent information, so accidental retrieval could expose private records or metadata the user did not explicitly request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The tool accepts a remote video URL and sends user-provided content to backend analysis without an explicit privacy warning. Because the content is videos of children and medical/behavioral analysis is highly sensitive, undisclosed transmission materially increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a specialized analysis/reporting tool, but the code also supports listing prior analyses for the current internal user. This mismatch is dangerous because users and reviewers may grant trust for one narrow purpose while the implementation performs broader account-data retrieval functions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script resolves an internal OpenID and uses it to access user-scoped analysis history via the --list path, even though the skill is presented as a video-analysis tool. This creates a privilege/scope expansion risk because account-linked data access is available without clear user disclosure, and the hidden open-id parameter increases the chance of unauthorized or confusing identity use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

A sensitive user identifier is resolved and used without clear user-facing disclosure. In a healthcare-adjacent autism analysis context, silent identity handling can expose personal analysis history and link sensitive behavioral data to an internal account without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The string literal returned on this line is fixed Chinese text, which indicates the skill presents output in a specific language regardless of user preference. Under the policy, language-specific behavior should either offer user opt-in or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2