Back to skill

Security audit

Smart Incontinence Status Alert Skill | 智能失禁状态提醒技能

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent as a cloud visual-analysis tool, but it handles very sensitive care media while silently creating or reusing identities, persisting tokens locally, and fetching cloud history records with limited user control.

Review this skill carefully before installing in any real caregiving setting. It may upload images, videos, URLs, and related report data to lifeemergence.com services, silently create or reuse an account identity, store tokens in a local SQLite database, and retrieve prior care reports from the cloud. Use it only where patients, guardians, or authorized caregivers have consented and where local/cloud data retention and access controls are acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (52)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The strongest mismatch reported includes local credential-like file access, workspace discovery, identity creation/reuse, database access, outbound HTTP requests, and automatic login/registration, none of which are disclosed by the caregiving description. Because the skill handles intimate medical-adjacent media, undisclosed credential, identity, and network behaviors create substantial privacy, consent, and unauthorized access risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The strongest mismatch reported includes local credential-like file access, workspace discovery, identity creation/reuse, database access, outbound HTTP requests, and automatic login/registration, none of which are disclosed by the caregiving description. Because the skill handles intimate medical-adjacent media, undisclosed credential, identity, and network behaviors create substantial privacy, consent, and unauthorized access risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The strongest mismatch reported includes local credential-like file access, workspace discovery, identity creation/reuse, database access, outbound HTTP requests, and automatic login/registration, none of which are disclosed by the caregiving description. Because the skill handles intimate medical-adjacent media, undisclosed credential, identity, and network behaviors create substantial privacy, consent, and unauthorized access risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The strongest mismatch reported includes local credential-like file access, workspace discovery, identity creation/reuse, database access, outbound HTTP requests, and automatic login/registration, none of which are disclosed by the caregiving description. Because the skill handles intimate medical-adjacent media, undisclosed credential, identity, and network behaviors create substantial privacy, consent, and unauthorized access risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The strongest mismatch reported includes local credential-like file access, workspace discovery, identity creation/reuse, database access, outbound HTTP requests, and automatic login/registration, none of which are disclosed by the caregiving description. Because the skill handles intimate medical-adjacent media, undisclosed credential, identity, and network behaviors create substantial privacy, consent, and unauthorized access risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The strongest mismatch reported includes local credential-like file access, workspace discovery, identity creation/reuse, database access, outbound HTTP requests, and automatic login/registration, none of which are disclosed by the caregiving description. Because the skill handles intimate medical-adjacent media, undisclosed credential, identity, and network behaviors create substantial privacy, consent, and unauthorized access risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The strongest mismatch reported includes local credential-like file access, workspace discovery, identity creation/reuse, database access, outbound HTTP requests, and automatic login/registration, none of which are disclosed by the caregiving description. Because the skill handles intimate medical-adjacent media, undisclosed credential, identity, and network behaviors create substantial privacy, consent, and unauthorized access risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The strongest mismatch reported includes local credential-like file access, workspace discovery, identity creation/reuse, database access, outbound HTTP requests, and automatic login/registration, none of which are disclosed by the caregiving description. Because the skill handles intimate medical-adjacent media, undisclosed credential, identity, and network behaviors create substantial privacy, consent, and unauthorized access risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The strongest mismatch reported includes local credential-like file access, workspace discovery, identity creation/reuse, database access, outbound HTTP requests, and automatic login/registration, none of which are disclosed by the caregiving description. Because the skill handles intimate medical-adjacent media, undisclosed credential, identity, and network behaviors create substantial privacy, consent, and unauthorized access risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The strongest mismatch reported includes local credential-like file access, workspace discovery, identity creation/reuse, database access, outbound HTTP requests, and automatic login/registration, none of which are disclosed by the caregiving description. Because the skill handles intimate medical-adjacent media, undisclosed credential, identity, and network behaviors create substantial privacy, consent, and unauthorized access risks.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "incontinence_alert_analysis"
description: "Automatically identifies wet clothing and abnormal excretion via visual AI. Instantly notifies caregivers to improve care for incontinent elderly, bedridden patients, and infants, reducing skin issues and complications. | 智能失禁状态提醒技能,基于视觉AI自动识别衣物潮湿、排泄异常等状况,第一时间推送通知给看护人员,提升失能老人、卧床病人、婴幼儿的护理质量,减少皮肤问题和并发症"
version: "1.0.17"
license: "MIT-0"
---

# 🚽 Smart Incontinence Status Alert Skill | 智能失禁状态提醒技能
> **智能�

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill processes highly sensitive image/video data involving elderly, bedridden patients, and infants, yet the description does not clearly warn users that such data may be transmitted to remote services for analysis and history lookup. This omission undermines informed consent and increases the risk of privacy violations, regulatory exposure, and unsafe sharing of intimate medical-adjacent media.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a narrowly scoped care skill that detects wet clothing and abnormal excretion and notifies caregivers. This file instead exposes a generic 'video analysis tool' interface, accepts arbitrary local or remote MP4 input, and retrieves analysis history via generic methods like get_output_analysis and get_output_analysis_list without any incontinence-specific logic or caregiver notification behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises and instructs use of shell execution, network access, local file handling, environment-derived identity handling, and possible local persistence, but declares no explicit tool scope or permission boundaries. In an agent setting this increases the chance of over-broad execution, accidental data exposure, and unsafe invocation of capabilities beyond what users would reasonably expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The history-report trigger phrases are broad enough that ordinary user requests may unintentionally invoke cloud history retrieval. In a sensitive caregiving context, accidental retrieval of prior reports could expose intimate patient monitoring records to users who only intended general discussion or local analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document says the skill uses a cloud visual AI service to analyze highly sensitive caregiving images, but it does not clearly disclose that images or derived data are uploaded off-device for remote processing. In this context, the subjects are elderly, bedridden patients, and infants, so the data may reveal intimate bodily conditions; lack of explicit disclosure and handling guidance materially increases privacy, consent, and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Natural-language strings throughout the tool, including errors, help text, and reports, are presented only in Chinese. This forces a specific language on users without opt-in or justification, which matches the locale policy violation criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script exposes a hidden record-listing capability that retrieves prior incontinence-analysis results by OpenID, even though the advertised purpose is analysis of current visual input. Because this skill handles highly sensitive health/care data, any unauthorized enumeration of historical records creates a significant privacy and confidentiality risk, especially if identity resolution can be influenced by the caller.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script allows analysis output containing sensitive care and possible health-condition data to be written to any local path without warning, minimization, or permission hardening. This can leave regulated or private data in insecure locations, where other local users, backup systems, or log collectors may access it unintentionally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The method returns a fixed Chinese-language heading string, with no indication that the user can choose or opt into this locale. This can violate language/locale policy when a skill imposes one language by default without documented justification or configurability.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Multiple user-visible strings are hardcoded in Chinese, including the report header and export-link text, with no indication that the user can opt into another language. This creates a locale policy concern because the skill enforces a specific language in its natural-language output without documented justification or user choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill accepts either arbitrary local files or arbitrary remote URLs and forwards them to a backend analysis service, even though the manifest describes a narrowly scoped incontinence-monitoring capability. This creates a scope-expansion and data-exfiltration risk because users or upstream agents can use the skill as a generic file/URL submission pipeline for unrelated, potentially sensitive media.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code reads full local file contents or accepts a remote video URL and submits that data to an analysis service without any visible consent prompt, minimization, or disclosure in the implementation. Because this skill processes intimate caregiving imagery and possible medical context, undisclosed transmission materially increases privacy, compliance, and data-handling risk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2