Back to skill

Security audit

Smart Feeder Pet Detection & Recognition Skill | 智能喂食器宠物检测识别技能

Security checks for vulnerabilities and agentic risk

Overview

The skill performs pet-camera cloud analysis, but it also silently creates or reuses cloud identities, stores account tokens locally, and accepts a hidden identity selector.

Review before installing. Use it only if you are comfortable sending pet camera images, videos, URLs, and report history to the configured cloud service, and with the skill creating or reusing local account tokens in the workspace data directory. Do not expose this skill to untrusted callers unless the hidden identity path is removed or strongly authenticated.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/pet_detection_feeder_analysis.py:228
Finding

Caller-Controlled Identity Enables Unauthorized Account Impersonation

Content
View full analysis

Vulnerability Details

File Location: scripts/pet_detection_feeder_analysis.py:228,245; skills/smyx_common/scripts/util.py:551-561,578-612
Vulnerability Type: Authentication bypass and account impersonation
Risk Level: High

Vulnerable Code

python
# scripts/pet_detection_feeder_analysis.py:228
parser.add_argument("--open-id", required=False, help=argparse.SUPPRESS)

# scripts/pet_detection_feeder_analysis.py:245
OpenIdUtil.resolve_current_open_id(
    args.open_id,
    use_current=bool(args.open_id)
)
python
# skills/smyx_common/scripts/util.py:551-561
_url = ApiEnum.BASE_URL_HEALTH + "/sys/phoneLogin"
open_id = username
_data = {
    "silent": 1,
    "register": 1,
    "openId": open_id,
    "mobile": username,
    "source": ConstantEnum.DEFAULT__SKILL_HUB_NAME
}
try:
    _response = requests.post(_url, json=_data)
    if _response.status_code == 200:
        _response_json = _response.json()
        if _response_json and _response_json.get("success"):
            return _response_json and _response_json.get("result")
python
# skills/smyx_common/scripts/util.py:578-612
current__user_name = (
    ApiEnum.API_SECRET_KEY
    or ConstantEnum.CURRENT__USER_NAME
    or ConstantEnum.CURRENT__OPEN_ID
)
found_user = None
if (not ApiEnum.TOKEN or not ApiEnum.OPEN_TOKEN) and current__user_name:
    try:
        from .dao import UserDao, User
        user_dao = UserDao()
        found_user = user_dao.get_by_username(current__user_name)
        if found_user:
            ApiEnum.TOKEN = found_user.token
            ApiEnum.OPEN_TOKEN = found_user.open_token
            current__user_name = found_user.username
        if not ApiEnum.TOKEN or not ApiEnum.OPEN_TOKEN:
            new_current_user = _get_or_create_user(current__user_name)
            if new_current_user:
                ApiEnum.TOKEN = new_current_user.get("token")
                ApiEnum.OPEN_TOKEN = new_current_user.get("openToken")

                current_user_info 
...[truncated 3581 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove --open-id from the public executable. If identity selection is operationally necessary, accept it only from a trusted, authenticated platform context rather than command-line input.

  2. Replace identifier-only silent login with a signed, short-lived identity assertion. The server should verify:

    • the assertion issuer;
    • the intended audience;
    • expiration and replay protection;
    • cryptographic integrity;
    • that the asserted subject matches the requested account.
  3. Require authenticated service credentials for the login or token-exchange endpoint. Do not issue account tokens solely from a caller-supplied username, mobile number, or OpenID.

  4. Disable automatic registration during ordinary analysis and history requests. Account provisioning should use a separate authenticated workflow.

  5. Bind every resulting token to the authenticated upstream subject and reject attempts to select a different identity.

  6. Validate authorization server-side for report listing, media analysis, and pet enrollment. Do not rely only on client-provided identity fields such as pnaUserName.

  7. Minimize bearer-token persistence. If local caching is required:

    • store tokens in an OS-protected credential store;
    • apply restrictive file permissions;
    • encrypt tokens at rest;
    • use short expiration periods and rotation;
    • delete invalid or expired tokens promptly.
  8. Add regression tests confirming that an arbitrary --open-id cannot obtain tokens, access reports, submit analysis, or enroll data for another account.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is the strongest form of the mismatch: the skill appears to perform generic HTTP communication, local file reads/writes, identity creation/reuse, token handling, auto-login/registration, and workspace-path management that are not implied by a simple pet feeder vision skill. In context, that is dangerous because uploaded media and user context may be sent to remote services and linked to persistent identities without clear consent or least-privilege boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This is the strongest form of the mismatch: the skill appears to perform generic HTTP communication, local file reads/writes, identity creation/reuse, token handling, auto-login/registration, and workspace-path management that are not implied by a simple pet feeder vision skill. In context, that is dangerous because uploaded media and user context may be sent to remote services and linked to persistent identities without clear consent or least-privilege boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This is the strongest form of the mismatch: the skill appears to perform generic HTTP communication, local file reads/writes, identity creation/reuse, token handling, auto-login/registration, and workspace-path management that are not implied by a simple pet feeder vision skill. In context, that is dangerous because uploaded media and user context may be sent to remote services and linked to persistent identities without clear consent or least-privilege boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This is the strongest form of the mismatch: the skill appears to perform generic HTTP communication, local file reads/writes, identity creation/reuse, token handling, auto-login/registration, and workspace-path management that are not implied by a simple pet feeder vision skill. In context, that is dangerous because uploaded media and user context may be sent to remote services and linked to persistent identities without clear consent or least-privilege boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is the strongest form of the mismatch: the skill appears to perform generic HTTP communication, local file reads/writes, identity creation/reuse, token handling, auto-login/registration, and workspace-path management that are not implied by a simple pet feeder vision skill. In context, that is dangerous because uploaded media and user context may be sent to remote services and linked to persistent identities without clear consent or least-privilege boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This is the strongest form of the mismatch: the skill appears to perform generic HTTP communication, local file reads/writes, identity creation/reuse, token handling, auto-login/registration, and workspace-path management that are not implied by a simple pet feeder vision skill. In context, that is dangerous because uploaded media and user context may be sent to remote services and linked to persistent identities without clear consent or least-privilege boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is the strongest form of the mismatch: the skill appears to perform generic HTTP communication, local file reads/writes, identity creation/reuse, token handling, auto-login/registration, and workspace-path management that are not implied by a simple pet feeder vision skill. In context, that is dangerous because uploaded media and user context may be sent to remote services and linked to persistent identities without clear consent or least-privilege boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is the strongest form of the mismatch: the skill appears to perform generic HTTP communication, local file reads/writes, identity creation/reuse, token handling, auto-login/registration, and workspace-path management that are not implied by a simple pet feeder vision skill. In context, that is dangerous because uploaded media and user context may be sent to remote services and linked to persistent identities without clear consent or least-privilege boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is the strongest form of the mismatch: the skill appears to perform generic HTTP communication, local file reads/writes, identity creation/reuse, token handling, auto-login/registration, and workspace-path management that are not implied by a simple pet feeder vision skill. In context, that is dangerous because uploaded media and user context may be sent to remote services and linked to persistent identities without clear consent or least-privilege boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is the strongest form of the mismatch: the skill appears to perform generic HTTP communication, local file reads/writes, identity creation/reuse, token handling, auto-login/registration, and workspace-path management that are not implied by a simple pet feeder vision skill. In context, that is dangerous because uploaded media and user context may be sent to remote services and linked to persistent identities without clear consent or least-privilege boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is the strongest form of the mismatch: the skill appears to perform generic HTTP communication, local file reads/writes, identity creation/reuse, token handling, auto-login/registration, and workspace-path management that are not implied by a simple pet feeder vision skill. In context, that is dangerous because uploaded media and user context may be sent to remote services and linked to persistent identities without clear consent or least-privilege boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is the strongest form of the mismatch: the skill appears to perform generic HTTP communication, local file reads/writes, identity creation/reuse, token handling, auto-login/registration, and workspace-path management that are not implied by a simple pet feeder vision skill. In context, that is dangerous because uploaded media and user context may be sent to remote services and linked to persistent identities without clear consent or least-privilege boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is the strongest form of the mismatch: the skill appears to perform generic HTTP communication, local file reads/writes, identity creation/reuse, token handling, auto-login/registration, and workspace-path management that are not implied by a simple pet feeder vision skill. In context, that is dangerous because uploaded media and user context may be sent to remote services and linked to persistent identities without clear consent or least-privilege boundaries.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "pet-detection-feeder-analysis"
description: "Based on computer vision, automatically detects and recognizes cats and dogs appearing in the target area from the perspective of feeder/IPC cameras, and supports pet identity recognition and database entry, suitable for pet identification management in smart feeding scenarios. | 智能喂食器宠物检测识别技能,基于计算机视觉从喂食器/IPC摄像头视角自动检测识别目标区域出现的猫、狗宠物,并支持宠物身份识别和底库录入,适用于智能喂养场景的宠物识别管理"
version: "1.0.18"
license: "MIT-0"
---

# 🍖 Smart Feeder

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The model stores token and open_token fields in a local shared SQLite database, but the skill purpose does not justify handling authentication tokens for users. Persisting tokens in a cross-skill shared database increases the blast radius of compromise and can enable account takeover or unauthorized API access if the database is read by other components or exfiltrated.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises and instructs use of shell execution, local file handling, network access, and environment-dependent behavior, but declares no explicit tool scope or permissions. This increases the blast radius because an agent may be allowed to invoke capabilities beyond what a user would reasonably expect from a pet-analysis skill, making misuse or overreach harder to constrain.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description promotes image/video analysis and history queries but does not clearly warn users that uploaded media and query-related data may be transmitted to a cloud API. In a pet-camera context this can expose household imagery, location cues, and behavioral history, making the omission a meaningful privacy and consent issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow states that uploaded attachments or media files are automatically saved locally, but there is no clear warning about local storage, retention, or cleanup. This is dangerous because camera images and videos may contain sensitive household content that persists on disk longer than users expect.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says this skill detects and recognizes cats and dogs from feeder/IPC camera views and supports identity recognition/database enrollment. However, this file is explicitly documented as storing 'pet health analysis API' interfaces and lists health-analysis endpoints, which contradicts the stated function of the skill rather than merely omitting details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The analyze_media function forwards local file paths or remote URLs to skill.get_output_analysis, which implies network submission to a backend analysis service, but the user is not explicitly warned that pet images/videos may leave the local environment. Since this skill handles camera media and pet identity enrollment, undisclosed transmission can expose sensitive household imagery and identity-linked metadata.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI exposes functionality beyond pet-media analysis by resolving an internal user identity and allowing history listing via a hidden --open-id and --list flow. Because these capabilities are not clearly disclosed to users and operate on account-scoped data, they can enable unintended access to analysis history or identity-linked data if invoked in broader agent workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code silently calls OpenIdUtil.resolve_current_open_id(...) before main processing, creating hidden identity resolution without meaningful user disclosure. In an agent setting, this can bind requests to an internal identity or retrieve account context unexpectedly, increasing privacy and access-control risk if users are unaware their identity is being inferred or applied.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple user-visible strings are hard-coded in Chinese, such as the report header and export-link message. This imposes a specific language on all users without offering a locale choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2