Back to skill

Security audit

Infant Stool Color Abnormality (Clay-Pale / Bloody) | 婴儿大便颜色识别(陶土色/血便)

Security checks for vulnerabilities and agentic risk

Overview

The skill is a Review case because it handles sensitive infant health images through cloud services while using unsafe default networking and silent identity/token persistence.

Install only if you are comfortable sending infant diaper/stool media and report queries to the publisher's cloud service and with the skill silently managing a local/backend identity. Before use, require HTTPS production endpoints, remove the dev configuration, fix image-only validation, make history lookup and uploads explicit opt-in actions, and protect or avoid persistent tokens.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/config-dev.yaml:2
Finding

Sensitive Medical Images and Authentication Credentials Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/util.py:572
Finding

Credential Disclosure through Unrestricted Absolute Request URLs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smyx_common/scripts/dao.py:460
Finding

Reusable Authentication Tokens Stored without Application-Level Protection

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skills/smyx_analysis/requirements.txt:3
Finding

Incorrect Dependency Distribution Name Creates Dependency-Confusion Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (62)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network requests, automatic account creation, token persistence, and workspace file access are significant backend and local capabilities not reflected in the narrow medical-screening description. In the context of infant-health data, hidden auth/session and persistence logic can enable excessive data retention, account confusion, and unauthorized access to sensitive reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Authenticated network requests, automatic account creation, token persistence, and workspace file access are significant backend and local capabilities not reflected in the narrow medical-screening description. In the context of infant-health data, hidden auth/session and persistence logic can enable excessive data retention, account confusion, and unauthorized access to sensitive reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Authenticated network requests, automatic account creation, token persistence, and workspace file access are significant backend and local capabilities not reflected in the narrow medical-screening description. In the context of infant-health data, hidden auth/session and persistence logic can enable excessive data retention, account confusion, and unauthorized access to sensitive reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network requests, automatic account creation, token persistence, and workspace file access are significant backend and local capabilities not reflected in the narrow medical-screening description. In the context of infant-health data, hidden auth/session and persistence logic can enable excessive data retention, account confusion, and unauthorized access to sensitive reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Authenticated network requests, automatic account creation, token persistence, and workspace file access are significant backend and local capabilities not reflected in the narrow medical-screening description. In the context of infant-health data, hidden auth/session and persistence logic can enable excessive data retention, account confusion, and unauthorized access to sensitive reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Authenticated network requests, automatic account creation, token persistence, and workspace file access are significant backend and local capabilities not reflected in the narrow medical-screening description. In the context of infant-health data, hidden auth/session and persistence logic can enable excessive data retention, account confusion, and unauthorized access to sensitive reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network requests, automatic account creation, token persistence, and workspace file access are significant backend and local capabilities not reflected in the narrow medical-screening description. In the context of infant-health data, hidden auth/session and persistence logic can enable excessive data retention, account confusion, and unauthorized access to sensitive reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network requests, automatic account creation, token persistence, and workspace file access are significant backend and local capabilities not reflected in the narrow medical-screening description. In the context of infant-health data, hidden auth/session and persistence logic can enable excessive data retention, account confusion, and unauthorized access to sensitive reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network requests, automatic account creation, token persistence, and workspace file access are significant backend and local capabilities not reflected in the narrow medical-screening description. In the context of infant-health data, hidden auth/session and persistence logic can enable excessive data retention, account confusion, and unauthorized access to sensitive reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network requests, automatic account creation, token persistence, and workspace file access are significant backend and local capabilities not reflected in the narrow medical-screening description. In the context of infant-health data, hidden auth/session and persistence logic can enable excessive data retention, account confusion, and unauthorized access to sensitive reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network requests, automatic account creation, token persistence, and workspace file access are significant backend and local capabilities not reflected in the narrow medical-screening description. In the context of infant-health data, hidden auth/session and persistence logic can enable excessive data retention, account confusion, and unauthorized access to sensitive reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network requests, automatic account creation, token persistence, and workspace file access are significant backend and local capabilities not reflected in the narrow medical-screening description. In the context of infant-health data, hidden auth/session and persistence logic can enable excessive data retention, account confusion, and unauthorized access to sensitive reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated network requests, automatic account creation, token persistence, and workspace file access are significant backend and local capabilities not reflected in the narrow medical-screening description. In the context of infant-health data, hidden auth/session and persistence logic can enable excessive data retention, account confusion, and unauthorized access to sensitive reports.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-infant-stool-color-abnormality-analysis"
description: "Using a fixed camera above the baby-changing table or a smartphone, the system captures high-resolution images of the diaper area (or the stool itself), and uses AI visual analysis to identify stool color: normal yellow / yellow-green, abnormal clay-pale (white/clay-like, suggesting biliary obstruction), bright red (lower-GI bleeding), dark red / tarry black (upper-GI bleeding), etc. | 通过婴儿护理台上方固定摄像头或手机拍摄尿不湿区域(或直接拍摄排泄物)的高清图像,利用AI视觉分析技术识别大便颜色,包括正常黄色/黄绿色�

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description does not clearly warn that sensitive infant images and report queries may be transmitted to remote cloud/API services. In this context, incomplete disclosure undermines informed consent and can lead to unauthorized exposure of highly sensitive child-health data and metadata.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Automatic fallback to a local default user and account creation is unrelated to image analysis and creates a serious risk of identity confusion or cross-user data mixing. For infant medical reports, silently reusing or creating identities can cause one person's reports to be associated with another session or exposed without meaningful consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation accepts video files and video URLs even though the skill is described as analyzing still images of infant stool color. This capability mismatch expands data collection beyond the stated purpose and increases privacy and compliance risk because diaper-area video is more sensitive, more voluminous, and easier to misuse than a single image.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The inline user-facing validation message says a local video path or network video URL is required, and nearby comments refer to video handling. This documentation-level framing conflicts with the manifest, which describes high-resolution image capture and analysis for stool color identification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation materially diverges from the declared skill purpose: it accepts local or remote MP4 video inputs and exposes video-history retrieval, while the manifest describes infant stool image-color analysis. In a sensitive pediatric/health context, this kind of capability mismatch is dangerous because users may unknowingly provide broader, more privacy-invasive footage than expected, and downstream systems may grant permissions or trust based on the manifest rather than the actual behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code reads a workspace identity file and, if absent, creates and persists a default user identity in a local database. For a medical-image analysis skill, this is an unjustified identity-management capability that can silently bind activity to local credentials or create shadow identities without user knowledge.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility performs authenticated API activity, token handling, local user lookup, and even automatic account provisioning, which is far beyond the declared purpose of infant stool-color image analysis. In this skill context, such hidden identity and network side effects materially increase the risk of unauthorized data transmission, account misuse, and covert expansion of capability without user awareness.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares broad operational behavior such as shell execution, network access, file read/write, and environment usage, but does not constrain those capabilities with an explicit tool scope. In an agent setting, undocumented broad capability combined with medical-image handling and cloud access increases the chance of unintended data exposure or misuse of local/system resources.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documentation expands from local visual analysis into cloud-based historical report retrieval and report-link output, introducing additional data flows for sensitive child-health information. Undeclared or weakly justified expansion of scope increases exposure of medical images and associated metadata beyond the immediate screening task.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

A default trigger that activates on any uploaded diaper-area image needing analysis is overly broad and can cause unintended invocation on sensitive infant imagery. Over-triggering in an agent environment risks accidental transmission or persistence of highly sensitive content without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Automatic cloud history lookup is not necessary for the core purpose of classifying stool color from a supplied image and introduces extra opportunities to access or disclose prior medical records. In a privacy-sensitive infant-health context, auto-triggered record retrieval can expose more data than the user intended to request.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2