Back to skill

Security audit

Fish Respiratory Rate (Gill Opening / Closing) Monitor | 鱼类呼吸频率(鳃盖开合)监测

Security checks for vulnerabilities and agentic risk

Overview

This fish-video analysis skill is mostly coherent, but it silently creates or reuses a cloud identity and persists authentication tokens for report access, which deserves review before installation.

Install only if you trust the publisher and are comfortable sending aquarium media or URLs to the configured cloud service. Be aware that the skill may create or reuse a local/cloud identity, keep tokens in a workspace SQLite database, and retrieve cloud report history automatically when prompted by history-related phrases.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (54)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose is a specialized fish-respiration analyzer, but the effective behavior includes external HTTP communication, authentication/token management, user/account lookup and creation, filesystem access, and environment detection. In this context, the mismatch is especially risky because the skill accepts local files and URLs, so hidden backend communication and identity operations could expose user media and metadata far beyond what the description implies.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose is a specialized fish-respiration analyzer, but the effective behavior includes external HTTP communication, authentication/token management, user/account lookup and creation, filesystem access, and environment detection. In this context, the mismatch is especially risky because the skill accepts local files and URLs, so hidden backend communication and identity operations could expose user media and metadata far beyond what the description implies.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is a specialized fish-respiration analyzer, but the effective behavior includes external HTTP communication, authentication/token management, user/account lookup and creation, filesystem access, and environment detection. In this context, the mismatch is especially risky because the skill accepts local files and URLs, so hidden backend communication and identity operations could expose user media and metadata far beyond what the description implies.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose is a specialized fish-respiration analyzer, but the effective behavior includes external HTTP communication, authentication/token management, user/account lookup and creation, filesystem access, and environment detection. In this context, the mismatch is especially risky because the skill accepts local files and URLs, so hidden backend communication and identity operations could expose user media and metadata far beyond what the description implies.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is a specialized fish-respiration analyzer, but the effective behavior includes external HTTP communication, authentication/token management, user/account lookup and creation, filesystem access, and environment detection. In this context, the mismatch is especially risky because the skill accepts local files and URLs, so hidden backend communication and identity operations could expose user media and metadata far beyond what the description implies.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is a specialized fish-respiration analyzer, but the effective behavior includes external HTTP communication, authentication/token management, user/account lookup and creation, filesystem access, and environment detection. In this context, the mismatch is especially risky because the skill accepts local files and URLs, so hidden backend communication and identity operations could expose user media and metadata far beyond what the description implies.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is a specialized fish-respiration analyzer, but the effective behavior includes external HTTP communication, authentication/token management, user/account lookup and creation, filesystem access, and environment detection. In this context, the mismatch is especially risky because the skill accepts local files and URLs, so hidden backend communication and identity operations could expose user media and metadata far beyond what the description implies.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is a specialized fish-respiration analyzer, but the effective behavior includes external HTTP communication, authentication/token management, user/account lookup and creation, filesystem access, and environment detection. In this context, the mismatch is especially risky because the skill accepts local files and URLs, so hidden backend communication and identity operations could expose user media and metadata far beyond what the description implies.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is a specialized fish-respiration analyzer, but the effective behavior includes external HTTP communication, authentication/token management, user/account lookup and creation, filesystem access, and environment detection. In this context, the mismatch is especially risky because the skill accepts local files and URLs, so hidden backend communication and identity operations could expose user media and metadata far beyond what the description implies.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is a specialized fish-respiration analyzer, but the effective behavior includes external HTTP communication, authentication/token management, user/account lookup and creation, filesystem access, and environment detection. In this context, the mismatch is especially risky because the skill accepts local files and URLs, so hidden backend communication and identity operations could expose user media and metadata far beyond what the description implies.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is a specialized fish-respiration analyzer, but the effective behavior includes external HTTP communication, authentication/token management, user/account lookup and creation, filesystem access, and environment detection. In this context, the mismatch is especially risky because the skill accepts local files and URLs, so hidden backend communication and identity operations could expose user media and metadata far beyond what the description implies.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The metadata triggered a tool/manifest poisoning rule, and while the visible snippet alone is not conclusive, suspicious or malformed manifest metadata combined with the broader description/behavior mismatch raises concern that the skill may be attempting to influence trust or routing through crafted metadata. In a skill manifest, any poisoning-like metadata is risky because downstream systems may use it for tool selection, policy decisions, or reviewer trust.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-fish-respiratory-rate-monitor-analysis"
description: "Through fixed cameras on aquariums, the system analyzes fish gill-cover opening / closing motion video, detects periodic gill opening and closing, and calculates respiratory rate (breaths per minute). | 通过鱼缸固定摄像头,分析鱼类的鳃盖开合运动视频,检测鳃盖的周期性开启和闭合,计算呼吸频率(次/分钟)。当呼吸频率超过正常阈值(例如 > 80 次/分钟,具体依品种和水温而定)时,输出'缺氧预警',提示用户检查水质(溶氧量)、水温或鱼的健康状态。"
version: "1.0.17"
license: "MIT-0"

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation is a broad remote API client rather than code specific to gill-motion or respiratory-rate analysis, which indicates capability drift beyond the declared skill scope. In a security review of agent skills, this mismatch is dangerous because it gives the skill undeclared external communication and data-manipulation capabilities that could be abused for lateral actions unrelated to aquarium monitoring.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file exposes generic wrappers for arbitrary HTTP methods (POST, PUT, GET, DELETE) and CRUD-style helpers that are not constrained to the stated fish respiratory-rate monitoring purpose. In an agent skill context, such unrestricted network primitives can be repurposed to access unrelated services, exfiltrate data, or perform unauthorized actions if other parts of the skill can influence URLs or request parameters.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file defines a full user-account data model and generic DAO supporting identity records and token-bearing fields, which is unrelated to the stated fish respiratory-rate monitoring purpose. This functionality creates an unjustified sensitive-data handling path that increases privacy, credential exposure, and misuse risk without clear business need. Purpose mismatch is especially suspicious because dormant account/token subsystems are often reused for hidden cross-skill state or unauthorized identity persistence.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The User model stores token and open_token fields alongside identity data, yet the manifest describes only aquarium video analysis and hypoxia alerts. Persisting authentication material without a clear functional need materially raises the consequences of local database compromise, accidental logging, or unauthorized cross-component reuse. In this skill context, the mismatch makes the data handling more dangerous because users would not reasonably expect credential storage from a fish-monitoring feature.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code generates or reuses user identities, reads a local API-key-derived identity file, and persists default usernames and tokens. For a fish breathing monitor, this behavior is unjustified and creates silent identity binding and credential lifecycle management that could be abused to track users, impersonate accounts, or link local execution to a remote service without informed consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility file contains broad remote account provisioning, token handling, and authenticated API request machinery that is unrelated to a fish respiratory-rate monitoring skill. In this context, the mismatch is dangerous because the skill gains networked identity and backend access capabilities far beyond what is needed for local video analysis, increasing the risk of covert data transmission, unauthorized account use, and privilege expansion.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill declares broad operational behavior including local file handling, shell execution, network access, and environment/identity use, but does not declare any corresponding tool scope or permissions boundary. This is dangerous because a reviewer or runtime policy engine cannot easily understand or constrain what the skill is allowed to do, increasing the chance of over-privileged execution and abuse if the backing scripts are invoked.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default trigger condition is broad enough to activate the skill whenever aquarium-related video or URL input is provided, even without a clear request for this specific analysis. This is dangerous because over-broad auto-invocation can cause unintended processing of user content, accidental transmission of files to remote services, and misuse of privileged capabilities without explicit consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The history-report auto-trigger keywords are broad and can initiate cloud record retrieval based on loosely matched phrases. This is dangerous because it may expose historical reports or linked report URLs without sufficiently strong contextual checks, particularly given the skill’s hidden identity association and automatic user-context reuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document title and all user-facing natural-language content are written exclusively in Chinese, with no indication that language selection is optional or limited to a China-specific deployment. Under the stated policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill exposes a history-listing function via show_analyze_list(open_id) that is not part of the declared fish respiratory-rate video analysis behavior. Hidden or unrelated data-access functionality expands the skill's effective scope and can enable unauthorized access to prior analysis records if invoked by a user or wrapper that can influence open_id or current identity state.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code initializes internal user identity with OpenIdUtil.resolve_current_open_id(...) and then uses ConstantEnum.CURRENT__OPEN_ID for listing history, even though the manifest describes only local or URL-based video analysis. This creates undisclosed identity-dependent behavior and ties a simple analysis tool to account-scoped data access, increasing the risk of privacy violations, cross-user data exposure, or hidden telemetry/data retrieval beyond user expectations.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2