Back to skill

Security audit

Employee Emotion Fluctuation HR Report | 员工入职/离职情绪波动预警(HR方向)

Security checks for vulnerabilities and agentic risk

Overview

This employee emotion-monitoring skill is mostly purpose-aligned, but it handles sensitive HR video/report data with persistent hidden identity and token mechanisms that need careful review before installation.

Install only in a formally approved HR environment with employee notice/consent, opt-out, legal review, strict administrator access, and audit logging. Review the vendor endpoints, local SQLite token storage, workspace data/smyx-api-key.txt behavior, retention promises, and historical report permissions before use; do not rely on the anonymization language alone.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (54)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymized, limited-purpose emotional monitoring, but the visible implementation includes filesystem access, environment discovery, reading local identity/credential files, persistent user creation, remote authenticated API access, and token storage. In an employee surveillance context, that combination is highly sensitive and materially expands the risk of identity linkage, credential exposure, and off-manifest data processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymized, limited-purpose emotional monitoring, but the visible implementation includes filesystem access, environment discovery, reading local identity/credential files, persistent user creation, remote authenticated API access, and token storage. In an employee surveillance context, that combination is highly sensitive and materially expands the risk of identity linkage, credential exposure, and off-manifest data processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymized, limited-purpose emotional monitoring, but the visible implementation includes filesystem access, environment discovery, reading local identity/credential files, persistent user creation, remote authenticated API access, and token storage. In an employee surveillance context, that combination is highly sensitive and materially expands the risk of identity linkage, credential exposure, and off-manifest data processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymized, limited-purpose emotional monitoring, but the visible implementation includes filesystem access, environment discovery, reading local identity/credential files, persistent user creation, remote authenticated API access, and token storage. In an employee surveillance context, that combination is highly sensitive and materially expands the risk of identity linkage, credential exposure, and off-manifest data processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymized, limited-purpose emotional monitoring, but the visible implementation includes filesystem access, environment discovery, reading local identity/credential files, persistent user creation, remote authenticated API access, and token storage. In an employee surveillance context, that combination is highly sensitive and materially expands the risk of identity linkage, credential exposure, and off-manifest data processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymized, limited-purpose emotional monitoring, but the visible implementation includes filesystem access, environment discovery, reading local identity/credential files, persistent user creation, remote authenticated API access, and token storage. In an employee surveillance context, that combination is highly sensitive and materially expands the risk of identity linkage, credential exposure, and off-manifest data processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymized, limited-purpose emotional monitoring, but the visible implementation includes filesystem access, environment discovery, reading local identity/credential files, persistent user creation, remote authenticated API access, and token storage. In an employee surveillance context, that combination is highly sensitive and materially expands the risk of identity linkage, credential exposure, and off-manifest data processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymized, limited-purpose emotional monitoring, but the visible implementation includes filesystem access, environment discovery, reading local identity/credential files, persistent user creation, remote authenticated API access, and token storage. In an employee surveillance context, that combination is highly sensitive and materially expands the risk of identity linkage, credential exposure, and off-manifest data processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymized, limited-purpose emotional monitoring, but the visible implementation includes filesystem access, environment discovery, reading local identity/credential files, persistent user creation, remote authenticated API access, and token storage. In an employee surveillance context, that combination is highly sensitive and materially expands the risk of identity linkage, credential exposure, and off-manifest data processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymized, limited-purpose emotional monitoring, but the visible implementation includes filesystem access, environment discovery, reading local identity/credential files, persistent user creation, remote authenticated API access, and token storage. In an employee surveillance context, that combination is highly sensitive and materially expands the risk of identity linkage, credential exposure, and off-manifest data processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymized, limited-purpose emotional monitoring, but the visible implementation includes filesystem access, environment discovery, reading local identity/credential files, persistent user creation, remote authenticated API access, and token storage. In an employee surveillance context, that combination is highly sensitive and materially expands the risk of identity linkage, credential exposure, and off-manifest data processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymized, limited-purpose emotional monitoring, but the visible implementation includes filesystem access, environment discovery, reading local identity/credential files, persistent user creation, remote authenticated API access, and token storage. In an employee surveillance context, that combination is highly sensitive and materially expands the risk of identity linkage, credential exposure, and off-manifest data processing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymized, limited-purpose emotional monitoring, but the visible implementation includes filesystem access, environment discovery, reading local identity/credential files, persistent user creation, remote authenticated API access, and token storage. In an employee surveillance context, that combination is highly sensitive and materially expands the risk of identity linkage, credential exposure, and off-manifest data processing.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The YARA hit indicates suspicious manifest metadata characteristics consistent with tool/metadata poisoning or malformed hidden content. While not definitive on its own, such anomalies are especially concerning in a skill that also requests broad capabilities and makes strong privacy assurances, because they can be used to influence downstream tooling or evade normal review.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-employee-emotion-fluctuation-hr-analysis"
description: "Using fixed cameras in enterprise office areas (with employee consent and anonymization), the system performs long-term monitoring of employees' facial expressions and posture features, building per-person historical baselines (smile frequency, sigh count, frown level, etc.). | 通过企业办公区固定摄像头(需征得员工同意并匿名化处理),长期监测员工的面部表情和姿态特征,建立个人历史基线(如笑容频率、叹气次数、皱眉程度等)。当检测到某员工近期的笑容频率显著下降(例如比基线降低40%)、叹�

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill claims no personal identifying information is stored and that reports remain anonymous, but also states that a persistent local default user may be auto-created and reused. Persistent user creation directly conflicts with the privacy narrative and can enable long-term linkage, audit gaps, or accidental exposure of sensitive HR-related report access patterns.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill claims no personal identifying information is stored and that reports remain anonymous, but also states that a persistent local default user may be auto-created and reused. Persistent user creation directly conflicts with the privacy narrative and can enable long-term linkage, audit gaps, or accidental exposure of sensitive HR-related report access patterns.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code reads an identity value from a workspace file and, if absent, silently creates and persists a default user identity in a local database. That behavior is unrelated to the declared HR analytics function and can cause undeclared identity creation, impersonation-like behavior, and hidden linkage of actions to a synthetic account.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares broad operational behavior including shell execution, local file handling, environment access, and network/API interaction, but provides no explicit tool scope or permissions boundary in the manifest. In an agent setting, this weakens least-privilege controls and can allow the skill to access more capabilities than users or reviewers would reasonably expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger rules are broad enough to activate on general workplace wellness or HR-related queries, which can cause the skill to run unexpectedly in contexts where users did not intend employee surveillance or sensitive report access. In a high-sensitivity domain, over-triggering increases the chance of inappropriate data processing and privacy-invasive responses.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill includes a cloud historical-report query function that goes beyond the manifest's core description of analyzing current camera input and producing alerts. Expanding into historical retrieval increases the privacy and authorization surface, especially for sensitive employee wellbeing data, and should be explicitly disclosed and access-controlled.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The notes instruct the skill to attach a specific hotline number, implying a fixed locale-specific support resource. There is no indication that users can choose an appropriate country/region resource or that the skill is limited to a specific jurisdiction where this hotline is valid.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents all operational and policy instructions only in Chinese, which imposes a specific language on users/readers without any opt-in or documented regional scope. Under the language/locale policy rule, this is a natural-language policy concern unless the document explicitly offers a language choice or states a justified locale limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The returned user-facing string is fixed in Chinese ("员工情绪波动 HR 报告结构化结果") with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This creates a natural-language locale policy concern because the skill appears to impose a specific language by default.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes long-term employee emotion monitoring from office cameras, yet the main analysis entrypoint accepts a pet_type parameter and mutates ConstantEnum.DEFAULT__PET_TYPE. This indicates the implemented behavior is reused from a pet-oriented pipeline rather than being aligned to the stated employee-emotion purpose, creating a semantic mismatch between the skill's declared function and actual code behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

All user-facing CLI descriptions and runtime messages are presented only in Chinese, with no option to select another language or locale. Under the policy, a skill should not force a specific language without user opt-in unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2