Back to skill

Security audit

Hydroponic Nutrient Concentration Visual Assessment | 水培植物营养液浓度视觉评估

Security checks for vulnerabilities and agentic risk

Overview

The skill is broadly a cloud-based hydroponic media analyzer, but it silently creates and reuses a user identity, stores tokens locally, and has implementation mismatches that merit review before installation.

Install only if you are comfortable sending plant images/videos or media URLs to the configured lifeemergence.com cloud service and having a persistent local user identity and cloud tokens stored in the workspace data database. Avoid using sensitive or unrelated media, and expect some rough edges because the implementation does not fully match the documented image-focused hydroponic workflow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (58)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound requests, local open-id generation/persistence, token handling, account bootstrap/login, and filesystem access represent a much broader and more sensitive behavior set than the stated hydroponic camera-analysis use case. This combination can enable silent user tracking, cloud account linkage, and persistent state creation without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Authenticated outbound requests, local open-id generation/persistence, token handling, account bootstrap/login, and filesystem access represent a much broader and more sensitive behavior set than the stated hydroponic camera-analysis use case. This combination can enable silent user tracking, cloud account linkage, and persistent state creation without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Authenticated outbound requests, local open-id generation/persistence, token handling, account bootstrap/login, and filesystem access represent a much broader and more sensitive behavior set than the stated hydroponic camera-analysis use case. This combination can enable silent user tracking, cloud account linkage, and persistent state creation without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound requests, local open-id generation/persistence, token handling, account bootstrap/login, and filesystem access represent a much broader and more sensitive behavior set than the stated hydroponic camera-analysis use case. This combination can enable silent user tracking, cloud account linkage, and persistent state creation without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Authenticated outbound requests, local open-id generation/persistence, token handling, account bootstrap/login, and filesystem access represent a much broader and more sensitive behavior set than the stated hydroponic camera-analysis use case. This combination can enable silent user tracking, cloud account linkage, and persistent state creation without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound requests, local open-id generation/persistence, token handling, account bootstrap/login, and filesystem access represent a much broader and more sensitive behavior set than the stated hydroponic camera-analysis use case. This combination can enable silent user tracking, cloud account linkage, and persistent state creation without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authenticated outbound requests, local open-id generation/persistence, token handling, account bootstrap/login, and filesystem access represent a much broader and more sensitive behavior set than the stated hydroponic camera-analysis use case. This combination can enable silent user tracking, cloud account linkage, and persistent state creation without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound requests, local open-id generation/persistence, token handling, account bootstrap/login, and filesystem access represent a much broader and more sensitive behavior set than the stated hydroponic camera-analysis use case. This combination can enable silent user tracking, cloud account linkage, and persistent state creation without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound requests, local open-id generation/persistence, token handling, account bootstrap/login, and filesystem access represent a much broader and more sensitive behavior set than the stated hydroponic camera-analysis use case. This combination can enable silent user tracking, cloud account linkage, and persistent state creation without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound requests, local open-id generation/persistence, token handling, account bootstrap/login, and filesystem access represent a much broader and more sensitive behavior set than the stated hydroponic camera-analysis use case. This combination can enable silent user tracking, cloud account linkage, and persistent state creation without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound requests, local open-id generation/persistence, token handling, account bootstrap/login, and filesystem access represent a much broader and more sensitive behavior set than the stated hydroponic camera-analysis use case. This combination can enable silent user tracking, cloud account linkage, and persistent state creation without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound requests, local open-id generation/persistence, token handling, account bootstrap/login, and filesystem access represent a much broader and more sensitive behavior set than the stated hydroponic camera-analysis use case. This combination can enable silent user tracking, cloud account linkage, and persistent state creation without clear disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated outbound requests, local open-id generation/persistence, token handling, account bootstrap/login, and filesystem access represent a much broader and more sensitive behavior set than the stated hydroponic camera-analysis use case. This combination can enable silent user tracking, cloud account linkage, and persistent state creation without clear disclosure.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

Metadata poisoning indicators in a skill manifest are suspicious because they can be used to confuse parsers, hide semantics, or manipulate tool/skill interpretation. In this context—where the skill already shows strong description-behavior mismatch—unusual manifest metadata increases concern that the packaging is intentionally or carelessly misleading.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-hydroponic-nutrient-assessment-analysis"
description: "Using fixed cameras on a hydroponic growing rack to capture high-resolution images of plant roots (in transparent containers) and leaves (young and old), AI vision analysis identifies root color (white = healthy, yellow = early stress, brown = severe stress, black = rotting) and leaf morphology (tip burn, leaf-margin scorch, yellowing, curling) to judge whether the nutrient solution is too concentrated or too dilute, and. | 通过水培种植架的固定摄像头拍摄植物根系(透明容器)和叶片(新叶、老叶)的高清图像,利用AI视觉分析技术识别根

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation materially diverges from the declared hydroponic root/leaf image-assessment purpose and instead exposes a generic video analysis and history-listing workflow. This kind of capability mismatch is dangerous because it can hide undeclared functionality from reviewers and operators, undermining trust boundaries and enabling the skill to process broader data types or workflows than users expect.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The model stores user identities and sensitive authentication material (token, open_token) with no clear need for a hydroponic nutrient assessment workflow. Unnecessary credential storage materially increases the impact of compromise, especially in a local shared SQLite database, and suggests overcollection beyond the skill's stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code automatically provisions identities, logs in to a remote service, retrieves tokens, and persists them locally, behavior that is unrelated to hydroponic image-based nutrient assessment. In a skill context, this creates undisclosed account creation and credential handling that can bind user activity to remote infrastructure and expand data exposure well beyond the stated purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill advertises and invokes capabilities consistent with shell, filesystem, environment, and network access, but the manifest does not declare an explicit tool scope or permission boundary. That makes the effective privilege surface opaque to reviewers and increases the chance that the agent can perform actions the user did not reasonably expect, including local file persistence and outbound API access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

An overly broad default trigger can cause the skill to activate on generic image-analysis requests, increasing the chance of unintended file handling, uploads, or history lookups outside the intended hydroponic context. When a skill also has network and persistence behaviors, over-triggering materially raises privacy and misuse risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs automatic local saving of uploaded files without a clear user-facing storage notice, creating undisclosed data persistence. This is risky because uploaded media may contain sensitive or unrelated content, and local retention expands exposure if the host is shared or later compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill requires direct cloud API queries for historical reports but does not clearly warn users that user-linked report data is being retrieved from a cloud service. This undermines informed consent and may expose prior analysis metadata associated with a persistent identity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Automatically creating or reusing a local default user identity is not justified by the visible task of analyzing plant images and creates silent cross-session linkage. This is dangerous because it enables persistent tracking and accidental access to prior reports or data associated with a reused local identity.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is documented and presented as a hydroponic plant image analysis tool, but the core entrypoint still accepts pet_type and sets ConstantEnum.DEFAULT__PET_TYPE, with CLI choices cat, dog, and other. This is an active contradiction between the code's stated purpose and the implementation-facing documentation/help text, indicating the file was repurposed from a pet-analysis skill without aligning behavior and intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The command description and argument help text are written only in Chinese, and the runtime status/error messages are also emitted only in Chinese. This imposes a fixed language on users without any documented locale choice or opt-in, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2