Back to skill

Security audit

Human Pose Recognition Skill | 人体姿态识别技能

Security checks for vulnerabilities and agentic risk

Overview

This posture-analysis skill may work through a cloud API, but it under-discloses sensitive video, identity, token, and history-report handling and ships a release configuration that sends those over plaintext HTTP development endpoints.

Install only after the publisher fixes the release configuration to use HTTPS production endpoints, documents exactly what media and identity data are uploaded or stored, narrows automatic report/history access, and avoids persisting reusable tokens unless clearly necessary and protected.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/config-dev.yaml:2
Finding

Sensitive Credentials, Identity Data, and Monitoring Videos Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (56)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "human-posture-recognition-analysis"
description: "Recognizes various poses such as standing, sitting, lying down, bending, raising hands, running, and falling. Supports abnormal pose recognition and fall warnings, suitable for security monitoring and elderly care. | 人体姿态识别技能,识别站立、坐姿、躺卧、弯腰、举手、奔跑、摔倒等多种人体姿态,支持肢体异常姿态识别和摔倒预警,适用于安防监测、老人看护等场景"
version: "1.0.15"
license: "MIT-0"
---

# 🧍 Human Pose Recognition Skill | 人体姿态识别技能
> **智能分析中枢** · 图片/视频智能分析

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file documents pet health analysis APIs even though the skill is ներկայացված as human posture recognition. This mismatch strongly suggests the skill package contains copied, stale, or misbound integration details, which can cause the agent to call unintended backend endpoints, expose unrelated data domains, or perform actions outside the declared scope. In a security-sensitive context like monitoring and elderly care, domain confusion increases the risk of privacy violations and unsafe automation decisions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements generic user account persistence, including identity fields and account lookup/update logic, which is materially unrelated to a human posture recognition skill. In this context, unexpected identity-management capability increases the risk of undisclosed data collection, lateral use of account data, and privilege creep far beyond the stated function of the skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The User model stores highly sensitive identity and authentication-related data, including username, real name, email, token, and open_token, which is unjustified for posture recognition. In a vision-monitoring or elderly-care context, hidden retention of identity and token material materially elevates privacy and account-compromise risk if the database is accessed, reused, or leaked.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

get_agent_skills_dir() resolves and creates the agent's skills directory, enabling code paths that can manipulate the installed skill environment rather than merely process posture data. That capability is dangerous because it can be used as a stepping stone for unauthorized skill installation, persistence, or tampering with adjacent components in the agent workspace.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This utility performs account discovery, implicit user creation, token acquisition, and persistence of authentication material through external login flows that are unrelated to human posture recognition. In the context of a vision/posture skill, this hidden identity bootstrapping broadens privileges and silently transmits identifiers to remote services, creating an unnecessary credential and privacy exposure surface.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documentation instructs use of shell, file, network, environment, and write-capable behaviors without declaring any tool scope or permission boundaries. This creates an unsafe trust gap: an agent may execute broad capabilities the user did not explicitly authorize, increasing the chance of unintended file access, network exfiltration, or command execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description does not clearly warn that local files or network URLs may be sent to a cloud API for processing. Because the content involves security monitoring and elderly care footage, omission of this disclosure materially increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The default activation condition appears to trigger on any provided monitoring video URL or file, even when the user may not have intended to invoke cloud-based posture analysis. This can cause unintended processing of sensitive media and silent transmission or storage of private footage.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The history-report trigger phrases are broad enough that ordinary conversational requests could unintentionally invoke remote history retrieval. That can expose prior report metadata or links without a sufficiently specific user request, especially in a surveillance or elder-care context where reports may be sensitive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation states that uploaded attachments or media files are automatically saved locally, but gives no explicit warning about storage, location, retention, or access controls. For surveillance and care footage, silent local persistence creates avoidable privacy exposure if the host is shared or compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation mandates silent creation or reuse of a local default user identity, which is unrelated to the core function of recognizing posture in a file or URL. Hidden identity creation enables tracking and report association without informed user consent, and in combination with local persistence may create privacy and data-retention issues.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says this skill performs human posture recognition for poses such as standing, sitting, running, and falling, but the only documentation in this file says 'Pet Analysis scripts package'. This is an active contradiction in inline documentation, suggesting the code/package labeling does not match the declared skill intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill sends local video paths or remote URLs to skill.get_output_analysis, which likely forwards sensitive posture/fall-monitoring footage to an external service, yet the tool provides no explicit privacy notice, consent prompt, or data-handling disclosure. Because the stated use cases include security monitoring and elderly care, the content can be highly sensitive and may expose personal, health-related, or behavioral information if transmitted unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI performs hidden identity resolution via OpenIdUtil.resolve_current_open_id and exposes a concealed --list history function using an internal/current OpenID, which exceeds the posture-recognition purpose described in the metadata. Hidden account-scoped history access increases the risk of unauthorized enumeration or disclosure of prior analysis activity, especially because the parameter is suppressed from help and not clearly disclosed to users.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2