Back to skill

Security audit

Flowering & Fruit Set Rate Analysis | 番茄/辣椒开花坐果率分析

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform remote media analysis, but it silently creates or reuses account identity, stores tokens locally, queries cloud history, and has several mismatches between its plant-analysis description and packaged code/docs.

Review this skill before installing. It is not just a local plant counter: it can send images, videos, or URLs to lifeemergence.com/open.lifeemergence.com services, silently create or reuse an internal account identity, store tokens in a local workspace database, and query cloud report history. Install only if that remote processing and account-linked history behavior is acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (57)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description claims local AI vision analysis of plant flowers and fruit set, but the documented behavior indicates generic remote API submission, history retrieval, identity handling, file persistence, and other undeclared functions unrelated to the stated purpose. This mismatch is dangerous because users and calling agents may provide sensitive files or trust outputs under false assumptions about what processing occurs and where their data is sent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description claims local AI vision analysis of plant flowers and fruit set, but the documented behavior indicates generic remote API submission, history retrieval, identity handling, file persistence, and other undeclared functions unrelated to the stated purpose. This mismatch is dangerous because users and calling agents may provide sensitive files or trust outputs under false assumptions about what processing occurs and where their data is sent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description claims local AI vision analysis of plant flowers and fruit set, but the documented behavior indicates generic remote API submission, history retrieval, identity handling, file persistence, and other undeclared functions unrelated to the stated purpose. This mismatch is dangerous because users and calling agents may provide sensitive files or trust outputs under false assumptions about what processing occurs and where their data is sent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description claims local AI vision analysis of plant flowers and fruit set, but the documented behavior indicates generic remote API submission, history retrieval, identity handling, file persistence, and other undeclared functions unrelated to the stated purpose. This mismatch is dangerous because users and calling agents may provide sensitive files or trust outputs under false assumptions about what processing occurs and where their data is sent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description claims local AI vision analysis of plant flowers and fruit set, but the documented behavior indicates generic remote API submission, history retrieval, identity handling, file persistence, and other undeclared functions unrelated to the stated purpose. This mismatch is dangerous because users and calling agents may provide sensitive files or trust outputs under false assumptions about what processing occurs and where their data is sent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description claims local AI vision analysis of plant flowers and fruit set, but the documented behavior indicates generic remote API submission, history retrieval, identity handling, file persistence, and other undeclared functions unrelated to the stated purpose. This mismatch is dangerous because users and calling agents may provide sensitive files or trust outputs under false assumptions about what processing occurs and where their data is sent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description claims local AI vision analysis of plant flowers and fruit set, but the documented behavior indicates generic remote API submission, history retrieval, identity handling, file persistence, and other undeclared functions unrelated to the stated purpose. This mismatch is dangerous because users and calling agents may provide sensitive files or trust outputs under false assumptions about what processing occurs and where their data is sent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description claims local AI vision analysis of plant flowers and fruit set, but the documented behavior indicates generic remote API submission, history retrieval, identity handling, file persistence, and other undeclared functions unrelated to the stated purpose. This mismatch is dangerous because users and calling agents may provide sensitive files or trust outputs under false assumptions about what processing occurs and where their data is sent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description claims local AI vision analysis of plant flowers and fruit set, but the documented behavior indicates generic remote API submission, history retrieval, identity handling, file persistence, and other undeclared functions unrelated to the stated purpose. This mismatch is dangerous because users and calling agents may provide sensitive files or trust outputs under false assumptions about what processing occurs and where their data is sent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description claims local AI vision analysis of plant flowers and fruit set, but the documented behavior indicates generic remote API submission, history retrieval, identity handling, file persistence, and other undeclared functions unrelated to the stated purpose. This mismatch is dangerous because users and calling agents may provide sensitive files or trust outputs under false assumptions about what processing occurs and where their data is sent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description claims local AI vision analysis of plant flowers and fruit set, but the documented behavior indicates generic remote API submission, history retrieval, identity handling, file persistence, and other undeclared functions unrelated to the stated purpose. This mismatch is dangerous because users and calling agents may provide sensitive files or trust outputs under false assumptions about what processing occurs and where their data is sent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description claims local AI vision analysis of plant flowers and fruit set, but the documented behavior indicates generic remote API submission, history retrieval, identity handling, file persistence, and other undeclared functions unrelated to the stated purpose. This mismatch is dangerous because users and calling agents may provide sensitive files or trust outputs under false assumptions about what processing occurs and where their data is sent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description claims local AI vision analysis of plant flowers and fruit set, but the documented behavior indicates generic remote API submission, history retrieval, identity handling, file persistence, and other undeclared functions unrelated to the stated purpose. This mismatch is dangerous because users and calling agents may provide sensitive files or trust outputs under false assumptions about what processing occurs and where their data is sent.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-flowering-fruit-set-rate-analysis-analysis"
description: "AI-powered flowering and fruit-set rate analysis for tomato / chili plants. From home grow-box or mobile phone images of flowering/fruit clusters, uses object-detection models to count open flowers (fully-opened corolla with visible stamens) and successfully-set young fruits (enlarged ovary, ~0.5-1cm green baby fruits), and computes fruit-set rate = young fruits / flowers × 100%. Helps growers evaluate pollination, nutrition and environmental adaptability, and guides hand-assisted pollination or water/fertilizer adjustment. Scenarios: home smart grow-boxes, greenhouses, balcony

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes analysis of plant flower/fruit cluster images from a grow-box or mobile phone to count flowers and young fruits. In contrast, this code explicitly expects a local video path or network video URL, populates a videoUrl parameter, and rejects missing input with a message requiring video input, indicating materially different behavior than the declared image-analysis scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The implementation materially contradicts the declared skill purpose: the manifest promises image-based flowering/fruit-set analysis, but the code performs video analysis and exposes video history listing. This kind of capability mismatch is dangerous because users, orchestrators, or policy engines may grant permissions, route data, or make trust decisions based on the manifest, while the code actually processes a different and potentially more privacy-sensitive data type and offers extra functionality.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code reads an identity value from a workspace file and, if absent, auto-generates and persists a default user record in a local database. For an image-analysis skill, silently deriving or creating identities is unjustified and can lead to opaque tracking, unintended account linkage, and unauthorized use of backend services under fabricated or inherited identities.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility code performs identity resolution, account provisioning, token handling, local user persistence, and general HTTP request capabilities that are far beyond the declared plant image-analysis purpose. That mismatch is dangerous because a seemingly innocuous vision skill can silently authenticate users, create accounts, and transmit data to external services, expanding the attack surface and violating least-privilege expectations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises and directs use of capabilities including shell execution, network access, local file handling, and environment-driven behavior, but does not declare any explicit tool scope or permission boundaries. In an agent environment, this increases the chance of over-privileged execution, unintended file access, or silent data exfiltration through the referenced scripts and APIs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The default trigger is broad enough to activate on general flower/fruit imagery and the history-query phrases are generic enough to overlap with ordinary conversation. In agent systems this can cause unintended invocation, accidental file processing, or unintended cloud/API queries without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The history-report trigger phrases are overly generic and may match casual user requests, causing the skill to automatically query cloud-side report history. Because the skill also describes automatic identity association, this can expose or retrieve prior records without a sufficiently explicit request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to provide local files or public URLs and describes cloud/API processing, but it does not present a clear privacy warning that uploaded files and URLs may be transmitted to remote services. This undermines informed consent and increases privacy risk, especially for photos, videos, metadata, and account-linked analysis history.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The API documentation is clearly mismatched with the declared skill purpose: it describes pet health analysis endpoints and scenario codes inside a plant flowering/fruit-set analysis skill. This kind of cross-domain mismatch is dangerous because it can cause the agent or integrator to call unrelated backend services, mishandle data, or expose unintended functionality and data paths.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The referenced API surface explicitly targets pet health analysis rather than the manifest's flowering/fruit-set use case, indicating either a packaging error or unintended service coupling. If used as-is, the skill could invoke the wrong APIs, send user data to an unrelated service, or grant access to historical reports and exports outside the intended domain.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill exposes a user-identity-based analysis history listing function that is unrelated to the stated image-analysis purpose. Features that enumerate prior results tied to an 'open_id' can expose historical user data or metadata if access control is weak, especially because the script presents this as a local CLI action without visible authorization checks.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2