Back to skill

Security audit

Baby Blanket Kick Monitoring Skill | 婴儿蹬被监测技能

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent baby-monitoring purpose, but it uploads sensitive infant media while silently managing identities and tokens, including insecure cleartext and plaintext storage paths that require review before installation.

Install only after the publisher explains and fixes the active dev HTTP configuration, documents where infant media and reports are uploaded and retained, and moves reusable tokens out of plaintext SQLite storage. Users should treat this as a sensitive cloud baby-monitoring integration, not a local-only detector.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/config.yaml:15
Finding

Sensitive Infant Footage and Authentication Credentials Transmitted over Cleartext HTTP

Content
View full analysis

Vulnerability Details

File Location: skills/smyx_common/scripts/config.yaml:15, skills/smyx_common/scripts/config.py:43-50, skills/smyx_common/scripts/config-dev.yaml:1-7, skills/smyx_analysis/scripts/skill.py:108-138, skills/smyx_common/scripts/util.py:543-561, 610-646
Vulnerability Type: Cleartext transmission of sensitive media, identity data, and authentication credentials
Risk Level: High

Vulnerable Code

skills/smyx_common/scripts/config.yaml:15:

yaml
env: dev

skills/smyx_common/scripts/config.py:43-50:

python
config_path = os.path.join(cls_dirpath, "config.yaml")
config = YamlUtil.load(config_path)
cls.init(config)
env = config.get("env")
if env:
    env_config_path = os.path.join(cls_dirpath, f"config-{env}.yaml")
    env_config = YamlUtil.load(env_config_path)
    cls.init(env_config)

skills/smyx_common/scripts/config-dev.yaml:1-7:

yaml
ApiEnum:
  base-url-open-api: "http://192.168.1.234:9601/smyx-open-api"
  base-url-open-h5: "http://192.168.1.234:4100"
  base-url-health: "http://192.168.1.234:7070/jeecg-boot-xzgz"

ConstantEnum:
  is-debug: true

skills/smyx_analysis/scripts/skill.py:108-138:

python
files = None

if not input_path:
    raise ValueError("必须提供本地视频路径(--input)或网络视频URL(--url)")

if (input_path.startswith("http://") or input_path.startswith("https://")):
    params.update({
        "videoUrl": input_path
    })
else:
    _validate_file(input_path)

    # 自动检测 MIME 类型
    mime_type, _ = mimetypes.guess_type(input_path)
    if mime_type is None:
        mime_type = 'application/octet-stream'

    # 读取文件内容
    with open(input_path, 'rb') as f:
        file_content = f.read()

    files = {
        'file': (os.path.basename(input_path), file_content, mime_type)
    }

open_id = argss.pop('open_id', None)
response = self.analysis(
    params=params,
    files=files
)

skills/smyx_common/scripts/util.py:543-561:

python
def _get_or_create_user(username):
    _url = ApiE
...[truncated 4037 chars]
Remediation
View remediation

Remediation Suggestions

  1. Change the release configuration to use the production environment and HTTPS-only endpoints.
  2. Remove env: dev and config-dev.yaml from production distributions, or require an explicit development-only opt-in.
  3. Reject API and authentication URLs whose scheme is not https.
  4. Do not permit silent fallback from HTTPS to HTTP.
  5. Retain normal TLS certificate and hostname verification; do not introduce verify=False.
  6. Rotate all authentication tokens that may have traversed the cleartext endpoints.
  7. Clearly disclose that infant footage is uploaded to an external service and obtain explicit user consent before transmission.
  8. Minimize transmitted metadata and avoid sending identity fields that are not required for analysis.
  9. Add automated tests that fail the build when active release endpoints use HTTP.
  10. Consider certificate pinning or equivalent endpoint trust controls where the deployment model supports secure lifecycle management.

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smyx_common/scripts/dao.py:175
Finding

Reusable Authentication Tokens Persisted in Plaintext SQLite Storage

Content
View full analysis

Vulnerability Details

File Location: skills/smyx_common/scripts/dao.py:175-180, skills/smyx_common/scripts/dao.py:448-462, skills/smyx_common/scripts/util.py:580-599
Vulnerability Type: Plaintext local storage of reusable authentication tokens
Risk Level: Medium

Vulnerable Code

skills/smyx_common/scripts/dao.py:175-180:

python
db_path = "smyx-common-claw.db"

self.engine = create_engine(f"sqlite:///{db_path}", echo=False)

skills/smyx_common/scripts/dao.py:448-462:

python
class User(Base, BaseModelMixin):
    __tablename__ = "sys_user"

    token = Column(String(500), comment="token")
    open_token = Column(String(1000), comment="开放token")
    source = Column(String(50), comment="token")

skills/smyx_common/scripts/util.py:580-599:

python
if (not ApiEnum.TOKEN or not ApiEnum.OPEN_TOKEN) and current__user_name:
    try:
        from .dao import UserDao, User
        user_dao = UserDao()
        found_user = user_dao.get_by_username(current__user_name)
        if found_user:
            ApiEnum.TOKEN = found_user.token
            ApiEnum.OPEN_TOKEN = found_user.open_token
            current__user_name = found_user.username
        if not ApiEnum.TOKEN or not ApiEnum.OPEN_TOKEN:
            new_current_user = _get_or_create_user(current__user_name)
            if new_current_user:
                ApiEnum.TOKEN = new_current_user.get("token")
                ApiEnum.OPEN_TOKEN = new_current_user.get("openToken")

                current_user_info = new_current_user.get("userInfo")
                if current_user_info:
                    current_user_info["token"] = new_current_user.get("token")
                    current_user_info["openToken"] = new_current_user.get(
                        "openToken")
                    user_model = User.load(current_user_info)

                    user = user_dao.save(
                        user_model
                    )

Technical Analysis

The Skill stores ...[truncated 2079 chars]

Remediation
View remediation

Remediation Suggestions

  1. Store reusable credentials in an operating-system credential manager or secrets service rather than in SQLite.
  2. If local persistence is unavoidable, encrypt tokens with a key stored separately in a protected keyring or hardware-backed secret store.
  3. Create credential files with owner-only permissions and verify those permissions before reading or writing.
  4. Use short-lived, narrowly scoped tokens and implement secure refresh-token rotation.
  5. Avoid persisting access tokens when reauthentication or ephemeral session credentials are practical.
  6. Revoke tokens when users sign out, uninstall the Skill, or reset the associated identity.
  7. Exclude credential databases from backups, diagnostic bundles, source-control operations, and workspace exports.
  8. Add a migration that removes or encrypts existing plaintext token values.
  9. Document the credential lifecycle, storage location, retention period, and revocation process.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (66)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated external API requests, create or reuse user identities/open IDs, persist token/user data locally, and read a local API-key-like file, while claiming only baby blanket monitoring. This combination is dangerous because it couples sensitive infant footage with hidden authentication, identity correlation, and credential handling that users are unlikely to anticipate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill appears to perform authenticated external API requests, create or reuse user identities/open IDs, persist token/user data locally, and read a local API-key-like file, while claiming only baby blanket monitoring. This combination is dangerous because it couples sensitive infant footage with hidden authentication, identity correlation, and credential handling that users are unlikely to anticipate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to perform authenticated external API requests, create or reuse user identities/open IDs, persist token/user data locally, and read a local API-key-like file, while claiming only baby blanket monitoring. This combination is dangerous because it couples sensitive infant footage with hidden authentication, identity correlation, and credential handling that users are unlikely to anticipate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated external API requests, create or reuse user identities/open IDs, persist token/user data locally, and read a local API-key-like file, while claiming only baby blanket monitoring. This combination is dangerous because it couples sensitive infant footage with hidden authentication, identity correlation, and credential handling that users are unlikely to anticipate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to perform authenticated external API requests, create or reuse user identities/open IDs, persist token/user data locally, and read a local API-key-like file, while claiming only baby blanket monitoring. This combination is dangerous because it couples sensitive infant footage with hidden authentication, identity correlation, and credential handling that users are unlikely to anticipate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to perform authenticated external API requests, create or reuse user identities/open IDs, persist token/user data locally, and read a local API-key-like file, while claiming only baby blanket monitoring. This combination is dangerous because it couples sensitive infant footage with hidden authentication, identity correlation, and credential handling that users are unlikely to anticipate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated external API requests, create or reuse user identities/open IDs, persist token/user data locally, and read a local API-key-like file, while claiming only baby blanket monitoring. This combination is dangerous because it couples sensitive infant footage with hidden authentication, identity correlation, and credential handling that users are unlikely to anticipate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to perform authenticated external API requests, create or reuse user identities/open IDs, persist token/user data locally, and read a local API-key-like file, while claiming only baby blanket monitoring. This combination is dangerous because it couples sensitive infant footage with hidden authentication, identity correlation, and credential handling that users are unlikely to anticipate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to perform authenticated external API requests, create or reuse user identities/open IDs, persist token/user data locally, and read a local API-key-like file, while claiming only baby blanket monitoring. This combination is dangerous because it couples sensitive infant footage with hidden authentication, identity correlation, and credential handling that users are unlikely to anticipate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated external API requests, create or reuse user identities/open IDs, persist token/user data locally, and read a local API-key-like file, while claiming only baby blanket monitoring. This combination is dangerous because it couples sensitive infant footage with hidden authentication, identity correlation, and credential handling that users are unlikely to anticipate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated external API requests, create or reuse user identities/open IDs, persist token/user data locally, and read a local API-key-like file, while claiming only baby blanket monitoring. This combination is dangerous because it couples sensitive infant footage with hidden authentication, identity correlation, and credential handling that users are unlikely to anticipate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to perform authenticated external API requests, create or reuse user identities/open IDs, persist token/user data locally, and read a local API-key-like file, while claiming only baby blanket monitoring. This combination is dangerous because it couples sensitive infant footage with hidden authentication, identity correlation, and credential handling that users are unlikely to anticipate.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The YARA hit suggests suspicious metadata-manifest characteristics consistent with tool/manifest poisoning, and the skill already shows multiple signs of mismatched purpose and hidden capabilities. While the match may be heuristic, in this context it raises concern that metadata is being used to shape trust or routing in ways not aligned with the real behavior.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "infant-blanket-kick-monitoring-analysis"
description: "Identifies babies kicking off blankets or exposing their bodies during sleep and alerts parents to cover them up to prevent catching a cold. | 婴儿蹬被监测技能,识别婴儿夜间睡觉踢开被子、身体裸露,及时提醒家长给宝宝盖被保暖,预防着凉感冒"
version: "1.0.13"
license: "MIT-0"
---

# 👶 Baby Blanket Kick Monitoring Skill | 婴儿蹬被监测技能
> **智能分析中枢** · 图片/视频智能分析 · 结构化报告 · 历史报告云端查询

---

## 🧭 技能概览 | Overview

| 模块 | 内容 |
|---|---|
| 🏷️ 技能名�

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill omits a clear privacy warning despite handling infant monitoring images/videos and querying cloud-based historical reports. Because the content involves recordings from a baby's sleeping area inside the home, lack of disclosure about upload, storage, retention, and account association materially increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The implementation is a generic file/URL submission client for remote analysis rather than a narrowly scoped infant blanket monitor. This scope mismatch is dangerous because it enables arbitrary local file exfiltration and remote content analysis under a benign-sounding skill description, reducing user scrutiny and increasing the chance of misuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation materially exceeds the stated purpose of infant blanket-kick monitoring by accepting arbitrary local files or remote URLs for generic analysis. That scope mismatch is dangerous because it can conceal a broader surveillance or data-processing capability than users expect, increasing the risk of unauthorized processing of unrelated videos and privacy-sensitive content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file exposes a generic API wrapper with create, edit, delete, and arbitrary HTTP GET/POST/PUT/DELETE methods that are not scoped to the declared infant blanket monitoring purpose. In a skill whose manifest describes a narrow monitoring function, such broad caller-controlled network capability increases the risk of hidden data exfiltration, unauthorized backend interaction, or repurposing the skill as a general remote action client.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The http_post, http_put, http_get, and http_delete methods accept caller-supplied URLs and forward requests directly, effectively providing arbitrary outbound network access. In the context of a baby monitoring skill, this is especially suspicious because it enables unrelated communications channels that could be used for command-and-control, data exfiltration, or contacting untrusted services.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file defines a generic sys_user model and DAO with identity fields, email, tokens, and account lookup/update logic that are unrelated to infant blanket-kick monitoring. In a narrowly scoped monitoring skill, hidden user/account persistence materially expands data collection and attack surface, increasing the risk of unauthorized retention, cross-feature tracking, or later abuse of stored credentials.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The model stores token and open_token values even though the skill's stated purpose is simply detecting blanket exposure during infant sleep. Storing authentication material without clear necessity creates a high-value secret store inside an unrelated skill; compromise of the local database could expose session or API credentials and enable account takeover or lateral access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility layer contains authenticated remote API access, token handling, local user persistence, and account bootstrapping logic that is unrelated to the stated infant blanket monitoring function. In a baby-monitoring skill, such broad hidden platform-integration capability expands the attack surface and enables undisclosed data transmission or remote actions under user-linked identities.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code silently logs in or auto-registers remote accounts by sending openId/mobile values and then stores tokens locally when no credentials are present. That behavior is unjustified for infant sleep monitoring and could bind a user or workspace to remote services without informed consent, enabling persistent identity tracking and unauthorized backend access.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool/permission scope even though its documented behavior includes shell execution, network access, local file handling, and environment/data access. In an agent environment, missing scope boundaries increases the chance of unintended or over-broad execution, especially since the skill accepts local files and remote URLs and instructs direct script execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The history-report trigger phrases are broad enough that normal user requests about reports could automatically invoke cloud history retrieval. In a sensitive infant-monitoring context, unintended retrieval of account-linked historical reports can expose private metadata or report links without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The document specifies that returned JSON fields should be automatically converted into a particular Markdown output format, and the overall instructions/examples are predominantly fixed in Chinese without indicating language selection or user preference. This creates a locale/language constraint that is not presented as optional or justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2