Back to skill

Security audit

Fish Isolation / Schooling Behavior Detection | 鱼类聚集/离群行为识别

Security checks for vulnerabilities and agentic risk

Overview

This aquarium-analysis skill should go to Review because it silently manages an internal account, uploads media to a cloud service, stores tokens locally, and currently defaults to development HTTP endpoints.

Review carefully before installing. Only use this if you are comfortable sending aquarium videos or video URLs to the publisher's cloud service and having a local internal account reused across runs. The publisher should switch the released config to HTTPS production endpoints, remove plaintext dev addresses, narrow the API surface, avoid plaintext token storage, document retention/deletion, and fix the dependency name before broad use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/config-dev.yaml:1
Finding

Sensitive identities, authentication tokens, and video data are transmitted over plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/dao.py:448
Finding

Authentication tokens are stored unencrypted in a shared SQLite database

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smyx_common/scripts/util.py:35
Finding

HTTP wire debugging can expose credentials and request bodies in logs

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skills/smyx_analysis/requirements.txt:3
Finding

Incorrect YAML dependency name creates dependency-confusion risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (56)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The strongest concern is that the skill combines authenticated external requests, automatic user identity/account creation, local file/database access, and runtime-context detection while lacking the promised fish-tracking logic. In a low-risk-seeming aquarium context, such hidden breadth is more dangerous because users and reviewers are less likely to expect or scrutinize identity linkage, persistence, and remote transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The strongest concern is that the skill combines authenticated external requests, automatic user identity/account creation, local file/database access, and runtime-context detection while lacking the promised fish-tracking logic. In a low-risk-seeming aquarium context, such hidden breadth is more dangerous because users and reviewers are less likely to expect or scrutinize identity linkage, persistence, and remote transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The strongest concern is that the skill combines authenticated external requests, automatic user identity/account creation, local file/database access, and runtime-context detection while lacking the promised fish-tracking logic. In a low-risk-seeming aquarium context, such hidden breadth is more dangerous because users and reviewers are less likely to expect or scrutinize identity linkage, persistence, and remote transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The strongest concern is that the skill combines authenticated external requests, automatic user identity/account creation, local file/database access, and runtime-context detection while lacking the promised fish-tracking logic. In a low-risk-seeming aquarium context, such hidden breadth is more dangerous because users and reviewers are less likely to expect or scrutinize identity linkage, persistence, and remote transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The strongest concern is that the skill combines authenticated external requests, automatic user identity/account creation, local file/database access, and runtime-context detection while lacking the promised fish-tracking logic. In a low-risk-seeming aquarium context, such hidden breadth is more dangerous because users and reviewers are less likely to expect or scrutinize identity linkage, persistence, and remote transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The strongest concern is that the skill combines authenticated external requests, automatic user identity/account creation, local file/database access, and runtime-context detection while lacking the promised fish-tracking logic. In a low-risk-seeming aquarium context, such hidden breadth is more dangerous because users and reviewers are less likely to expect or scrutinize identity linkage, persistence, and remote transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The strongest concern is that the skill combines authenticated external requests, automatic user identity/account creation, local file/database access, and runtime-context detection while lacking the promised fish-tracking logic. In a low-risk-seeming aquarium context, such hidden breadth is more dangerous because users and reviewers are less likely to expect or scrutinize identity linkage, persistence, and remote transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The strongest concern is that the skill combines authenticated external requests, automatic user identity/account creation, local file/database access, and runtime-context detection while lacking the promised fish-tracking logic. In a low-risk-seeming aquarium context, such hidden breadth is more dangerous because users and reviewers are less likely to expect or scrutinize identity linkage, persistence, and remote transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The strongest concern is that the skill combines authenticated external requests, automatic user identity/account creation, local file/database access, and runtime-context detection while lacking the promised fish-tracking logic. In a low-risk-seeming aquarium context, such hidden breadth is more dangerous because users and reviewers are less likely to expect or scrutinize identity linkage, persistence, and remote transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The strongest concern is that the skill combines authenticated external requests, automatic user identity/account creation, local file/database access, and runtime-context detection while lacking the promised fish-tracking logic. In a low-risk-seeming aquarium context, such hidden breadth is more dangerous because users and reviewers are less likely to expect or scrutinize identity linkage, persistence, and remote transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The strongest concern is that the skill combines authenticated external requests, automatic user identity/account creation, local file/database access, and runtime-context detection while lacking the promised fish-tracking logic. In a low-risk-seeming aquarium context, such hidden breadth is more dangerous because users and reviewers are less likely to expect or scrutinize identity linkage, persistence, and remote transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The strongest concern is that the skill combines authenticated external requests, automatic user identity/account creation, local file/database access, and runtime-context detection while lacking the promised fish-tracking logic. In a low-risk-seeming aquarium context, such hidden breadth is more dangerous because users and reviewers are less likely to expect or scrutinize identity linkage, persistence, and remote transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The strongest concern is that the skill combines authenticated external requests, automatic user identity/account creation, local file/database access, and runtime-context detection while lacking the promised fish-tracking logic. In a low-risk-seeming aquarium context, such hidden breadth is more dangerous because users and reviewers are less likely to expect or scrutinize identity linkage, persistence, and remote transmission.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-fish-isolation-detection-analysis"
description: "Through fixed cameras on aquariums, the system continuously tracks the 2D position of each fish in the school, computes the school centroid (center of mass), and measures the distance from each fish to the centroid (in units of fish body length). | 通过鱼缸固定摄像头,持续跟踪鱼群中每条鱼的二维位置,计算鱼群中心(质心),并检测每条鱼与中心的距离(以鱼体长为单位)。当某条鱼偏离鱼群中心超过 10 倍体长,且持续时间超过 1 小时(或用户设定阈值)时,输出'离群行为'提示。"
version: "1.0.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This module exposes broad generic CRUD and arbitrary HTTP request helpers that are not constrained to the stated fish-isolation analytics purpose. In a skill that should analyze aquarium video/telemetry, these wrappers materially expand capability to interact with unrelated backend services, increasing the risk of unauthorized data access, modification, or abuse if other components can invoke them.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements generic local user/account persistence, schema migration, and shared workspace database handling, which is unrelated to the stated fish-isolation analytics purpose. Such capability expansion increases attack surface and creates an unjustified foothold for storing identities, tokens, and cross-skill state in a context that should only perform video-derived fish behavior analysis.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The User model stores identity and authentication-related fields including username, realname, email, token, and open_token, none of which are needed for aquarium fish isolation detection. In this skill context, collecting and persisting such data is especially suspicious because it enables credential/token retention and user profiling outside the declared feature scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code generates synthetic open IDs, reuses local identities, and persists them to local storage/database even when the user did not provide one. For a fish-behavior analysis skill, silent identity creation is unjustified and dangerous because it can establish tracking or backend accounts without user awareness and can be combined with later network calls.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The utility layer performs remote login/registration, token acquisition, token caching, and authenticated API calls that are unrelated to the declared fish-isolation camera analysis purpose. This creates hidden network side effects and can exfiltrate identifiers or bind the runtime to external accounts/services without informed user consent, which is especially suspicious given the narrow manifest scope.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises and instructs use of shell, file, network, environment, and local persistence capabilities but does not declare any explicit tool/permission scope. That weakens containment and reviewability, making it easier for a skill to access local files, invoke commands, and contact remote services beyond what a caller may expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Automatic local file saving and persistent daily report generation exceed the simple alerting behavior described in the high-level manifest. Undeclared persistence increases privacy and retention risk, especially for uploaded media and derived behavioral reports tied to a tank or user identity.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The default trigger is broad enough to activate on generic fish-video analysis requests, which can cause the skill to run in contexts the user did not clearly intend. Overbroad triggering is risky when the skill also performs file saving, cloud queries, and remote API submission.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation expands the skill from behavioral analysis into cloud history querying and report-link retrieval, increasing the operational scope beyond the manifest’s analytics framing. Scope expansion matters because it changes what data may be accessed and transmitted, potentially surprising users and reviewers.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

One section says uploaded media is automatically saved locally, while another says complete aquarium videos must not be stored long-term and gives a 7-day limit. This inconsistency is dangerous because it leaves actual retention behavior ambiguous, increasing the chance of accidental over-retention of sensitive media.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states that uploaded media is automatically saved locally but does not provide a clear upfront warning in the triggering/consent flow. Silent local storage of user-provided videos is a privacy issue, particularly when the skill is presented as straightforward behavior analysis.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2