T09 · Insecure Skill Coding Practices
- Location
skills/smyx_common/scripts/config-dev.yaml:2- Finding
Sensitive Credentials, Identity Data, and Monitoring Videos Transmitted over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This posture-analysis skill may work through a cloud API, but it under-discloses sensitive video, identity, token, and history-report handling and ships a release configuration that sends those over plaintext HTTP development endpoints.
Install only after the publisher fixes the release configuration to use HTTPS production endpoints, documents exactly what media and identity data are uploaded or stored, narrows automatic report/history access, and avoids persisting reusable tokens unless clearly necessary and protected.
skills/smyx_common/scripts/config-dev.yaml:2Sensitive Credentials, Identity Data, and Monitoring Videos Transmitted over Plaintext HTTP
The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.
The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.
The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.
The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.
The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.
The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.
The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.
The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.
The described implementation includes external API communication, token acquisition, local workspace discovery, identity generation, persistence, and database interaction unrelated to pose analysis. In a skill handling potentially sensitive monitoring footage, this broader behavior materially increases the risk of data leakage, unauthorized correlation of users with reports, and abuse of local or remote resources.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
---
name: "human-posture-recognition-analysis"
description: "Recognizes various poses such as standing, sitting, lying down, bending, raising hands, running, and falling. Supports abnormal pose recognition and fall warnings, suitable for security monitoring and elderly care. | 人体姿态识别技能,识别站立、坐姿、躺卧、弯腰、举手、奔跑、摔倒等多种人体姿态,支持肢体异常姿态识别和摔倒预警,适用于安防监测、老人看护等场景"
version: "1.0.15"
license: "MIT-0"
---
# 🧍 Human Pose Recognition Skill | 人体姿态识别技能
> **智能分析中枢** · 图片/视频智能分析
The file documents pet health analysis APIs even though the skill is ներկայացված as human posture recognition. This mismatch strongly suggests the skill package contains copied, stale, or misbound integration details, which can cause the agent to call unintended backend endpoints, expose unrelated data domains, or perform actions outside the declared scope. In a security-sensitive context like monitoring and elderly care, domain confusion increases the risk of privacy violations and unsafe automation decisions.
The file implements generic user account persistence, including identity fields and account lookup/update logic, which is materially unrelated to a human posture recognition skill. In this context, unexpected identity-management capability increases the risk of undisclosed data collection, lateral use of account data, and privilege creep far beyond the stated function of the skill.
The User model stores highly sensitive identity and authentication-related data, including username, real name, email, token, and open_token, which is unjustified for posture recognition. In a vision-monitoring or elderly-care context, hidden retention of identity and token material materially elevates privacy and account-compromise risk if the database is accessed, reused, or leaked.
get_agent_skills_dir() resolves and creates the agent's skills directory, enabling code paths that can manipulate the installed skill environment rather than merely process posture data. That capability is dangerous because it can be used as a stepping stone for unauthorized skill installation, persistence, or tampering with adjacent components in the agent workspace.
This utility performs account discovery, implicit user creation, token acquisition, and persistence of authentication material through external login flows that are unrelated to human posture recognition. In the context of a vision/posture skill, this hidden identity bootstrapping broadens privileges and silently transmits identifiers to remote services, creating an unnecessary credential and privacy exposure surface.
The skill documentation instructs use of shell, file, network, environment, and write-capable behaviors without declaring any tool scope or permission boundaries. This creates an unsafe trust gap: an agent may execute broad capabilities the user did not explicitly authorize, increasing the chance of unintended file access, network exfiltration, or command execution.
The skill description does not clearly warn that local files or network URLs may be sent to a cloud API for processing. Because the content involves security monitoring and elderly care footage, omission of this disclosure materially increases privacy and compliance risk.
The default activation condition appears to trigger on any provided monitoring video URL or file, even when the user may not have intended to invoke cloud-based posture analysis. This can cause unintended processing of sensitive media and silent transmission or storage of private footage.
The history-report trigger phrases are broad enough that ordinary conversational requests could unintentionally invoke remote history retrieval. That can expose prior report metadata or links without a sufficiently specific user request, especially in a surveillance or elder-care context where reports may be sensitive.
The documentation states that uploaded attachments or media files are automatically saved locally, but gives no explicit warning about storage, location, retention, or access controls. For surveillance and care footage, silent local persistence creates avoidable privacy exposure if the host is shared or compromised.
The documentation mandates silent creation or reuse of a local default user identity, which is unrelated to the core function of recognizing posture in a file or URL. Hidden identity creation enables tracking and report association without informed user consent, and in combination with local persistence may create privacy and data-retention issues.
The manifest says this skill performs human posture recognition for poses such as standing, sitting, running, and falling, but the only documentation in this file says 'Pet Analysis scripts package'. This is an active contradiction in inline documentation, suggesting the code/package labeling does not match the declared skill intent.
The skill sends local video paths or remote URLs to skill.get_output_analysis, which likely forwards sensitive posture/fall-monitoring footage to an external service, yet the tool provides no explicit privacy notice, consent prompt, or data-handling disclosure. Because the stated use cases include security monitoring and elderly care, the content can be highly sensitive and may expose personal, health-related, or behavioral information if transmitted unexpectedly.
The CLI performs hidden identity resolution via OpenIdUtil.resolve_current_open_id and exposes a concealed --list history function using an internal/current OpenID, which exceeds the posture-recognition purpose described in the metadata. Hidden account-scoped history access increases the risk of unauthorized enumeration or disclosure of prior analysis activity, especially because the parameter is suppressed from help and not clearly disclosed to users.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)
result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
dict) else result_json
if result_json_common_ai_response:
result_json = result_json_common_ai_response
Detected: suspicious.install_untrusted_source