Back to skill

Security audit

Greenhouse Climate Plant Feedback Analysis | 温室环境与植物状态联动调控

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it automatically uses a cloud service, creates or reuses an internal identity, and persists authentication tokens for history/report access without a strong user consent boundary.

Install only if you are comfortable sending greenhouse images/videos or URLs to the configured lifeemergence.com cloud service and having the skill create/reuse a workspace identity with locally stored tokens. Before use, confirm the backend account, retention expectations, and whether history lookups should require explicit user confirmation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest describes a greenhouse control skill, but the documented and inferred behavior includes generic remote API access, identity handling, local persistence, and historical record retrieval that are not transparently aligned with that purpose. This kind of capability mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under false assumptions, while hidden data access and external communication occur in the background.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest describes a greenhouse control skill, but the documented and inferred behavior includes generic remote API access, identity handling, local persistence, and historical record retrieval that are not transparently aligned with that purpose. This kind of capability mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under false assumptions, while hidden data access and external communication occur in the background.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The manifest describes a greenhouse control skill, but the documented and inferred behavior includes generic remote API access, identity handling, local persistence, and historical record retrieval that are not transparently aligned with that purpose. This kind of capability mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under false assumptions, while hidden data access and external communication occur in the background.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The manifest describes a greenhouse control skill, but the documented and inferred behavior includes generic remote API access, identity handling, local persistence, and historical record retrieval that are not transparently aligned with that purpose. This kind of capability mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under false assumptions, while hidden data access and external communication occur in the background.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The manifest describes a greenhouse control skill, but the documented and inferred behavior includes generic remote API access, identity handling, local persistence, and historical record retrieval that are not transparently aligned with that purpose. This kind of capability mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under false assumptions, while hidden data access and external communication occur in the background.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The manifest describes a greenhouse control skill, but the documented and inferred behavior includes generic remote API access, identity handling, local persistence, and historical record retrieval that are not transparently aligned with that purpose. This kind of capability mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under false assumptions, while hidden data access and external communication occur in the background.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest describes a greenhouse control skill, but the documented and inferred behavior includes generic remote API access, identity handling, local persistence, and historical record retrieval that are not transparently aligned with that purpose. This kind of capability mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under false assumptions, while hidden data access and external communication occur in the background.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest describes a greenhouse control skill, but the documented and inferred behavior includes generic remote API access, identity handling, local persistence, and historical record retrieval that are not transparently aligned with that purpose. This kind of capability mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under false assumptions, while hidden data access and external communication occur in the background.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest describes a greenhouse control skill, but the documented and inferred behavior includes generic remote API access, identity handling, local persistence, and historical record retrieval that are not transparently aligned with that purpose. This kind of capability mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under false assumptions, while hidden data access and external communication occur in the background.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest describes a greenhouse control skill, but the documented and inferred behavior includes generic remote API access, identity handling, local persistence, and historical record retrieval that are not transparently aligned with that purpose. This kind of capability mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under false assumptions, while hidden data access and external communication occur in the background.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest describes a greenhouse control skill, but the documented and inferred behavior includes generic remote API access, identity handling, local persistence, and historical record retrieval that are not transparently aligned with that purpose. This kind of capability mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under false assumptions, while hidden data access and external communication occur in the background.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest describes a greenhouse control skill, but the documented and inferred behavior includes generic remote API access, identity handling, local persistence, and historical record retrieval that are not transparently aligned with that purpose. This kind of capability mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under false assumptions, while hidden data access and external communication occur in the background.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest describes a greenhouse control skill, but the documented and inferred behavior includes generic remote API access, identity handling, local persistence, and historical record retrieval that are not transparently aligned with that purpose. This kind of capability mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under false assumptions, while hidden data access and external communication occur in the background.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest describes a greenhouse control skill, but the documented and inferred behavior includes generic remote API access, identity handling, local persistence, and historical record retrieval that are not transparently aligned with that purpose. This kind of capability mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under false assumptions, while hidden data access and external communication occur in the background.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-greenhouse-climate-plant-feedback-analysis"
description: "Using fixed cameras in a smart greenhouse to analyze plant morphology in real time (e.g., leaf wilting angle, stem uprightness, leaf color changes) combined with environmental sensors (light intensity, temperature, humidity, soil moisture), an AI decision model outputs climate control commands including irrigation (pump/solenoid valve), shade-net opening, fan/wet-curtain on-off, heater on-off, etc. | 通过智能温室中的固定摄像头实时分析植物的形态(如叶片萎蔫角度、茎秆挺直度、叶色变化)以及结合环境传感器(光照强度、温度、�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation materially diverges from the declared greenhouse-control purpose: instead of plant morphology plus environmental-sensor analysis and climate-control decisions, it exposes a generic video-analysis/history client. This kind of capability mismatch is dangerous because users and orchestrators may grant the skill permissions, trust, or deployment context appropriate for greenhouse actuation while the code performs different operations, enabling misuse, data exfiltration, or deceptive behavior under a misleading manifest.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The HTTP helper automatically performs external login/registration, derives tokens, stores them locally, and then uses them for subsequent API calls. For a greenhouse morphology and climate-control skill, this is unrelated privileged behavior that can silently bind the environment to remote accounts and transmit data under implicit authentication.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill advertises and instructs use of shell, network, file read/write, and environment-backed behavior, but declares no explicit tool scope or permissions boundary. In an agent setting, this weakens least-privilege controls and can allow broader-than-expected execution paths, especially when the skill also instructs automatic local file saving and cloud API access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description and overview emphasize closed-loop control that outputs actionable climate control commands such as irrigation, shading, ventilation, and heating. However, the declared output capability is limited to structured analysis reports, recognition/monitoring results, and suggestions/report links, which materially understates or reframes the operational behavior as reporting rather than command generation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The AI role section explicitly says to output environmental control action commands and priority only, and not detailed control parameters. Later workflow/output sections describe the result as a structured analysis report with monitoring results, suggestions, and links, which is a direct contradiction about the intended behavior and output format.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

A default trigger that activates on general greenhouse image or video analysis requests is overly broad for a skill that can save files locally and invoke remote services. In agent environments, broad auto-invocation increases the chance of unintended data processing, external transmission, or action recommendations without clear user consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The keyword trigger list is expansive and can match many ordinary greenhouse-related conversations, making accidental invocation more likely. Because the skill can perform automatic history queries and local file handling, unintended activation can expose private records or process data the user did not mean to submit to this workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill states that uploaded attachments are automatically saved as local files, but the description does not provide a clear user-facing warning or consent boundary for that behavior. Silent local persistence of user uploads can create data leakage, retention, and cross-task exposure risks in shared agent workspaces.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill auto-queries cloud APIs for historical reports tied to an internally managed identity, but this behavior is not clearly surfaced as a user-consent and privacy boundary. Hidden identity-linked lookups are particularly sensitive because they can reveal prior records or profile-linked data without the user understanding that a remote retrieval is happening.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The user-facing string on L17 is written only in Chinese, and this file provides no indication that the skill offers a language selection or that it is intentionally limited to a Chinese-language context. Under the policy, hard-coding a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2