Back to skill

Security audit

Family Conflict Aftercare Suggestion | 夫妻/家人冲突后情绪缓和提示

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent as a cloud video-analysis tool, but it handles very sensitive household conflict recordings with under-scoped identity handling and a release configuration that can send media and tokens over plaintext HTTP.

Review before installing. This skill uploads or references household camera audio/video and can query cloud history tied to an automatically managed identity. Do not use it unless you are comfortable with cloud processing of domestic conflict footage, have consent from affected household members, and can verify the package uses HTTPS production endpoints rather than the bundled development HTTP configuration.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/config-dev.yaml:2
Finding

Sensitive Household Media, Identity Data, and Authentication Tokens Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (59)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This finding combines several undeclared sensitive behaviors: external API communication, token/authorization management, remote user/open-id resolution or registration, local workspace data access, and directory discovery. For a domestic-conflict skill, hidden identity correlation and remote transmission of household media/metadata are especially dangerous because they can expose intimate family events and enable unanticipated cross-session tracking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding combines several undeclared sensitive behaviors: external API communication, token/authorization management, remote user/open-id resolution or registration, local workspace data access, and directory discovery. For a domestic-conflict skill, hidden identity correlation and remote transmission of household media/metadata are especially dangerous because they can expose intimate family events and enable unanticipated cross-session tracking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This finding combines several undeclared sensitive behaviors: external API communication, token/authorization management, remote user/open-id resolution or registration, local workspace data access, and directory discovery. For a domestic-conflict skill, hidden identity correlation and remote transmission of household media/metadata are especially dangerous because they can expose intimate family events and enable unanticipated cross-session tracking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding combines several undeclared sensitive behaviors: external API communication, token/authorization management, remote user/open-id resolution or registration, local workspace data access, and directory discovery. For a domestic-conflict skill, hidden identity correlation and remote transmission of household media/metadata are especially dangerous because they can expose intimate family events and enable unanticipated cross-session tracking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding combines several undeclared sensitive behaviors: external API communication, token/authorization management, remote user/open-id resolution or registration, local workspace data access, and directory discovery. For a domestic-conflict skill, hidden identity correlation and remote transmission of household media/metadata are especially dangerous because they can expose intimate family events and enable unanticipated cross-session tracking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding combines several undeclared sensitive behaviors: external API communication, token/authorization management, remote user/open-id resolution or registration, local workspace data access, and directory discovery. For a domestic-conflict skill, hidden identity correlation and remote transmission of household media/metadata are especially dangerous because they can expose intimate family events and enable unanticipated cross-session tracking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding combines several undeclared sensitive behaviors: external API communication, token/authorization management, remote user/open-id resolution or registration, local workspace data access, and directory discovery. For a domestic-conflict skill, hidden identity correlation and remote transmission of household media/metadata are especially dangerous because they can expose intimate family events and enable unanticipated cross-session tracking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding combines several undeclared sensitive behaviors: external API communication, token/authorization management, remote user/open-id resolution or registration, local workspace data access, and directory discovery. For a domestic-conflict skill, hidden identity correlation and remote transmission of household media/metadata are especially dangerous because they can expose intimate family events and enable unanticipated cross-session tracking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding combines several undeclared sensitive behaviors: external API communication, token/authorization management, remote user/open-id resolution or registration, local workspace data access, and directory discovery. For a domestic-conflict skill, hidden identity correlation and remote transmission of household media/metadata are especially dangerous because they can expose intimate family events and enable unanticipated cross-session tracking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding combines several undeclared sensitive behaviors: external API communication, token/authorization management, remote user/open-id resolution or registration, local workspace data access, and directory discovery. For a domestic-conflict skill, hidden identity correlation and remote transmission of household media/metadata are especially dangerous because they can expose intimate family events and enable unanticipated cross-session tracking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding combines several undeclared sensitive behaviors: external API communication, token/authorization management, remote user/open-id resolution or registration, local workspace data access, and directory discovery. For a domestic-conflict skill, hidden identity correlation and remote transmission of household media/metadata are especially dangerous because they can expose intimate family events and enable unanticipated cross-session tracking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding combines several undeclared sensitive behaviors: external API communication, token/authorization management, remote user/open-id resolution or registration, local workspace data access, and directory discovery. For a domestic-conflict skill, hidden identity correlation and remote transmission of household media/metadata are especially dangerous because they can expose intimate family events and enable unanticipated cross-session tracking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding combines several undeclared sensitive behaviors: external API communication, token/authorization management, remote user/open-id resolution or registration, local workspace data access, and directory discovery. For a domestic-conflict skill, hidden identity correlation and remote transmission of household media/metadata are especially dangerous because they can expose intimate family events and enable unanticipated cross-session tracking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding combines several undeclared sensitive behaviors: external API communication, token/authorization management, remote user/open-id resolution or registration, local workspace data access, and directory discovery. For a domestic-conflict skill, hidden identity correlation and remote transmission of household media/metadata are especially dangerous because they can expose intimate family events and enable unanticipated cross-session tracking.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill handles highly sensitive in-home audio/video surveillance data and cloud-accessible reports, yet the description lacks a clear warning about these privacy implications. Users may not realize that intimate domestic interactions, minors, and conflict history could be analyzed, stored, or transmitted, which is particularly dangerous in a household monitoring context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This utility automatically provisions or reuses backend identities, retrieves tokens, and persists them locally, even though the skill's stated purpose is family-conflict monitoring and aftercare. In this context, hidden identity creation and token storage materially expand the skill's privileges and enable undisclosed backend access that could be abused for tracking, impersonation, or unauthorized API activity.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares no explicit tool scope even though the documented behavior and underlying capabilities include shell, network, environment access, and local file read/write. In a skill handling highly sensitive in-home audio/video and identity-linked history, missing permission boundaries materially increases the chance of overbroad data access, unintended execution paths, and unsafe future extension.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest focuses on conflict detection and post-conflict soothing prompts, but the role definition adds immediate redirection to a 'safety risk' path with domestic-violence, police, and psychological-aid hotlines. This is a materially different intervention capability from aftercare prompting and is not declared in the manifest description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions hard-code China-specific hotlines and police contacts ('12338', '110', '400-161-9995') as the immediate response path. This is a locale-specific policy choice presented as mandatory, with no user opt-in or alternative for users in other languages or regions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

A broad default trigger that activates on any uploaded home camera media can cause accidental analysis of intimate household footage without a clear, specific request. Because the content involves in-home surveillance and potentially conflict/abuse detection, unintended invocation can expose highly sensitive family interactions to cloud APIs, local storage, and identity-linked reporting.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation expands the skill from local aftercare prompting into cloud-based historical report querying and report-link output. In a family-conflict context, that feature materially changes the data-sensitivity profile by enabling retrieval and sharing of relationship-conflict history, which can expose deeply private behavioral patterns if not clearly disclosed and access-controlled.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The notes require immediate push of specific Chinese emergency contacts when a critical redline is triggered. Because this requirement is unconditional and not documented as region-specific, it violates the language/locale policy by forcing a single locale-specific response.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The string returned on L17 is a user-facing heading written entirely in Chinese, and the file provides no indication that the skill is region-specific or that users can opt into this language. That creates a natural-language policy concern because the skill appears to force a specific language/locale by default.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest is specifically about detecting family conflict events from living-room/kitchen audio-video and providing aftercare suggestions. This function accepts a pet_type parameter and mutates ConstantEnum.DEFAULT__PET_TYPE, which indicates reuse of animal-classification context not justified by the stated family-conflict purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The argparse description and help text describe a family emotional de-escalation tool, yet the same CLI exposes --pet-type choices of cat, dog, and other. This is an active contradiction between the user-facing documentation and the actual interface semantics, suggesting the implementation was repurposed from a pet-related skill without being fully aligned.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2