Back to skill

Security audit

Fruit Ripeness Grading | 番茄/草莓果实成熟度分级

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a cloud-backed media analysis client, but its hidden identity handling and persistent token storage create account and history-access risks beyond a simple fruit ripeness grader.

Install only if you are comfortable with this skill sending media and user-linked report requests to LifeEmergence cloud APIs, creating local workspace identity/token records, and retrieving historical reports automatically. Avoid using it in shared or multi-user environments until identity selection is server-verified and history access requires explicit confirmation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/smyx_fruit_ripeness_grading_analysis.py:43
Finding

Caller-Controlled Open ID Enables Cross-User Account Impersonation

Content
View full analysis

Vulnerability Details

File Location: scripts/smyx_fruit_ripeness_grading_analysis.py:43-58; skills/smyx_common/scripts/util.py:449-462, 552-563, 576-612
Vulnerability Type: Improper authentication and user-controlled identity assertion
Risk Level: High

Complete Code Snippets

scripts/smyx_fruit_ripeness_grading_analysis.py:43-58:

python
parser.add_argument("--open-id", required=False, help=argparse.SUPPRESS)
parser.add_argument("--list", action='store_true', help="显示宠物健康分析列表清单")
parser.add_argument("--api-url", help="服务端API地址")
parser.add_argument("--api-key", help=argparse.SUPPRESS)
parser.add_argument("--output", help="结果输出文件路径")
parser.add_argument("--detail", choices=["basic", "standard", "json"],
                    default=ConstantEnum.DEFAULT__OUTPUT_LEVEL,
                    help="输出详细程度")
parser.add_argument("--export-env-only", action='store_true',
                    help="仅输出 export 命令设置环境变量,不执行分析")

args = parser.parse_args()

try:
    # 初始化内部用户身份;不要求用户输入,也不在帮助信息中展示。
    OpenIdUtil.resolve_current_open_id(args.open_id, use_current=bool(args.open_id))

skills/smyx_common/scripts/util.py:449-462:

python
def resolve_current_open_id(cls, open_id=None, use_current=True):
    """解析并初始化当前 open-id,返回最终使用值。"""
    resolved_open_id = (open_id or "").strip() if isinstance(open_id, str) else open_id
    if not resolved_open_id and use_current:
        resolved_open_id = ConstantEnum.CURRENT__OPEN_ID or ConstantEnum.CURRENT__USER_NAME
    if not resolved_open_id:
        resolved_open_id = cls.get_api_key_file_open_id()
    if not resolved_open_id:
        resolved_open_id = cls.get_or_create_default_open_id()

    ConstantEnum.CURRENT__OPEN_ID = resolved_open_id
    if not ConstantEnum.CURRENT__USER_NAME:
        ConstantEnum.CURRENT__USER_NAME = resolved_open_id
    return resolved_open_id

skills/smyx_common/scripts/util.py:552-563:

`` ...[truncated 5039 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove --open-id from the public CLI and do not permit ordinary callers to select an account identity.
  2. Obtain identity only from an authenticated, integrity-protected upstream context. Use a signed assertion with issuer, audience, expiration, and nonce validation.
  3. Require the server to verify ownership before issuing tokens. An identifier alone must never be sufficient for login or token creation.
  4. Disable silent registration/login for arbitrary supplied identifiers. Registration and authentication should be separate, explicitly authorized operations.
  5. Bind report queries to the subject encoded in the authenticated server-issued token rather than accepting a client-selected user identifier.
  6. If an internal identity override is operationally necessary, restrict it to an administrator-only interface and require explicit authorization checks, audit logging, and a narrowly scoped impersonation grant.
  7. Avoid storing tokens obtained through unverified identity assertions. Invalidate any tokens previously issued through this flow and review associated access logs for cross-account activity.
  8. Add negative authorization tests proving that one user cannot obtain credentials or report records by submitting another user’s Open ID.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (57)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authenticated HTTP communication, token/account retrieval, open-id generation, workspace discovery, and retry logic reveal a much broader authenticated integration than the description suggests. This can expose user identity, enable account correlation, and increase the blast radius if the skill or backend is compromised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Authenticated HTTP communication, token/account retrieval, open-id generation, workspace discovery, and retry logic reveal a much broader authenticated integration than the description suggests. This can expose user identity, enable account correlation, and increase the blast radius if the skill or backend is compromised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authenticated HTTP communication, token/account retrieval, open-id generation, workspace discovery, and retry logic reveal a much broader authenticated integration than the description suggests. This can expose user identity, enable account correlation, and increase the blast radius if the skill or backend is compromised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authenticated HTTP communication, token/account retrieval, open-id generation, workspace discovery, and retry logic reveal a much broader authenticated integration than the description suggests. This can expose user identity, enable account correlation, and increase the blast radius if the skill or backend is compromised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authenticated HTTP communication, token/account retrieval, open-id generation, workspace discovery, and retry logic reveal a much broader authenticated integration than the description suggests. This can expose user identity, enable account correlation, and increase the blast radius if the skill or backend is compromised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated HTTP communication, token/account retrieval, open-id generation, workspace discovery, and retry logic reveal a much broader authenticated integration than the description suggests. This can expose user identity, enable account correlation, and increase the blast radius if the skill or backend is compromised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated HTTP communication, token/account retrieval, open-id generation, workspace discovery, and retry logic reveal a much broader authenticated integration than the description suggests. This can expose user identity, enable account correlation, and increase the blast radius if the skill or backend is compromised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated HTTP communication, token/account retrieval, open-id generation, workspace discovery, and retry logic reveal a much broader authenticated integration than the description suggests. This can expose user identity, enable account correlation, and increase the blast radius if the skill or backend is compromised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated HTTP communication, token/account retrieval, open-id generation, workspace discovery, and retry logic reveal a much broader authenticated integration than the description suggests. This can expose user identity, enable account correlation, and increase the blast radius if the skill or backend is compromised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated HTTP communication, token/account retrieval, open-id generation, workspace discovery, and retry logic reveal a much broader authenticated integration than the description suggests. This can expose user identity, enable account correlation, and increase the blast radius if the skill or backend is compromised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated HTTP communication, token/account retrieval, open-id generation, workspace discovery, and retry logic reveal a much broader authenticated integration than the description suggests. This can expose user identity, enable account correlation, and increase the blast radius if the skill or backend is compromised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated HTTP communication, token/account retrieval, open-id generation, workspace discovery, and retry logic reveal a much broader authenticated integration than the description suggests. This can expose user identity, enable account correlation, and increase the blast radius if the skill or backend is compromised.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-fruit-ripeness-grading-analysis"
description: "AI-powered fruit ripeness grading for tomatoes / strawberries. From smart grow-boxes or mobile phone images, uses AI vision to detect fruit color (green / light green / orange / red / dark red), colored-area ratio, gloss, and relative fruit size (against a reference object), and outputs a ripeness grade (Mature-Green / Turning / Ripe / Over-Ripe) based on preset standards. Helps growers identify the optimal harvest window and ensures flavor and shelf quality. Scenarios: smart grow-boxes, greenhouses, home vegetable gardens, fruit & vegetable cooperatives. | 通过智能种植箱�

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file documents pet health analysis endpoints inside a skill that is supposed to perform fruit ripeness grading, which is a strong cross-domain mismatch. This can cause the agent or integrators to invoke unrelated health-report APIs, exposing sensitive pet-health data or enabling unintended backend access because the documented interfaces and scenario codes do not match the advertised skill purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The implementation materially diverges from the declared skill purpose: instead of fruit-image ripeness grading, it performs generic video analysis and accepts arbitrary local paths or remote URLs. This kind of scope mismatch is dangerous because it can conceal broader data-processing behavior than users or reviewers expect, undermining informed consent and making it easier to exfiltrate or process unrelated media.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The CLI and docstrings repeatedly present this as a 'video analysis tool,' which directly contradicts the declared fruit-image ripeness grading intent. Such contradictory documentation is a security concern because it signals undisclosed functionality and increases the chance that users provide sensitive video data under false assumptions about what the skill does.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This module includes persistent user-account storage and mutation logic, including usernames, tokens, open_token values, update methods, and deletion behavior, which is unrelated to a fruit ripeness grading skill. In context, this broadens the skill's access and persistence surface significantly, increasing the risk of unnecessary collection, modification, or leakage of user identity and credential-like data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code resolves an open-id by reading workspace files, reusing local database identities, or generating and persisting a new default user identity automatically. For a fruit grading skill this is unnecessary and dangerous because it silently establishes a durable identity layer that can be reused for backend access and user tracking without transparent user action.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This shared utility performs remote authentication, account bootstrap/provisioning, token handling, and authenticated API requests that are unrelated to the stated fruit-ripeness image analysis purpose. That mismatch materially increases risk because installing or invoking a seemingly local vision skill can silently contact external services, create backend identities, and transmit user-linked data without clear necessity or consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes shell commands, accesses local files, uses networked APIs, and appears to persist data, but the manifest declares no explicit tool permissions or allowed-tools scope. This creates a transparency and governance gap: the runtime may grant broader capabilities than users and reviewers expect, increasing the risk of unintended file access, command execution, or outbound data transfer.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill says it should only output visual maturity grading, but other sections add harvest advice, report retrieval, and link generation. This inconsistency widens the operational scope and can conceal extra processing and data access behind a simpler stated purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatic historical cloud report querying and report-link generation expand the skill from current-image analysis into retrieval of prior user-associated records. That creates additional privacy and access-control risk, especially because the retrieval is triggered by natural-language phrases and tied to internal identity handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Broad trigger phrases for historical report access can cause the skill to activate data-retrieval behaviors on ambiguous user requests. In practice, that may expose prior records or initiate cloud queries when the user only intended general discussion, increasing privacy and surprise-action risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs automatic local saving of uploaded files without a clear user-facing notice about storage and retention. Because the input is user-provided media, silent persistence increases privacy risk and may violate least-surprise expectations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest and top-level CLI description say this skill grades tomato/strawberry ripeness, but the argument documentation exposes a 'pet-type' selector with values like cat/dog and a '--list' help string for a pet health analysis list. These inline help texts actively describe a different skill domain, contradicting the code's stated fruit-analysis intent.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2