T09 · Insecure Skill Coding Practices
- Location
skills/smyx_common/scripts/util.py:423- Finding
Automatic Identity Transmission and Plaintext Authentication Token Storage
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s pet-video cloud analysis purpose is mostly coherent, but it silently creates or reuses an identity and persists service tokens locally, which requires review before installation.
Review this skill before installing. It sends videos or video URLs to lifeemergence.com/open.lifeemergence.com services and may link results to an automatically chosen identity. It can silently create or reuse a service account and store reusable authentication tokens in a local workspace database, so only install it if you accept that identity linkage, local credential persistence, and cloud report history access.
skills/smyx_common/scripts/util.py:423Automatic Identity Transmission and Plaintext Authentication Token Storage
skills/smyx_common/scripts/util.py:445Authentication Headers Can Be Disclosed to Arbitrary Absolute URLs
Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.
Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.
Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.
Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.
Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.
Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.
Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.
Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.
Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.
The YARA hit indicates suspicious metadata/manifest characteristics consistent with tool or metadata poisoning patterns. While the matched snippet alone is weak evidence, in the context of multiple description-behavior mismatches and undeclared capabilities, malformed or overloaded metadata increases the risk that the manifest is being used to obscure true behavior or influence tool routing improperly.
---
name: "smyx-pet-toy-interaction-activity-analysis"
description: "Triggers when a user provides a pet toy area video URL or file for analysis; supports local video uploads or network URLs to call server-side APIs for toy interaction behavior recognition, tracking interaction frequency, duration, and toy preference per pet, generating daily activity curves and trend comparisons to detect declining activity that may indicate illness or depression. Application scenarios: smart pet toys, pet wellness monitoring. | 当用户提供玩具区域视频URL或文件时,触发本技能进行互动行为分析;支持通过上传本地视频或网络视�
The skill accepts local files and remote URLs and states that server-side APIs will be called, but it does not clearly warn users that uploaded media or referenced URLs will be transmitted to cloud services. This is a significant privacy and consent issue, especially for user-provided videos that may contain sensitive household, location, or identifying information.
The code creates and persists synthetic user identities when no user identity is provided, including reading an identity from a workspace file, reusing a locally stored account, or generating a new one and saving it. For a pet toy video analysis skill, this exceeds the stated purpose and silently establishes persistent identity state that can be used to impersonate users or tie activity to undeclared accounts.
The HTTP helper automatically triggers phone-login/registration, retrieves tokens, and stores them locally for reuse. That behavior is unrelated to simple pet video analysis and creates hidden account provisioning and session persistence, which can be abused for unauthorized service access or silent account linking.
The skill advertises and instructs use of shell execution, network access, local file reads/writes, and environment-dependent behavior, but it declares no explicit tool scope or permission boundaries. That makes the skill capable of broader operations than a reviewer or runtime policy can easily constrain, increasing the chance of unintended data access or command execution.
The trigger phrases include broad wellness and behavior terms that could activate the skill in unrelated conversations, causing unintended processing of attachments or cloud queries. In a skill that can save local files and call remote APIs, over-triggering increases the chance of accidental data disclosure or execution of undesired workflows.
The skill metadata says it is triggered to analyze a provided toy-area video URL or file, but the code also exposes a history-listing mode that retrieves prior analysis records by open_id. That expands the data access scope beyond the stated purpose and can enable unauthorized or unexpected access to historical pet activity data if invoked through the agent or CLI.
The argument parser description and help text are presented only in Chinese, and the runtime status/error messages are likewise hard-coded to a single language. This forces a specific language for all users without any documented locale choice or opt-in.
The code resolves and uses an internal open_id without clear user-facing disclosure, and can optionally take a hidden --open-id parameter. Hidden identity binding increases the risk of processing or exposing another user's historical analysis data without informed consent, especially because the same identity is later used for list retrieval.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)
result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
dict) else result_json
if result_json_common_ai_response:
result_json = result_json_common_ai_response
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)
result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
dict) else result_json
if result_json_common_ai_response:
result_json = result_json_common_ai_response
Multiple returned status and result strings are fixed in Chinese, which forces a specific language for user-visible interaction. The file does not offer localization, user opt-in, or any justification that the skill is intended only for a Chinese-speaking or region-specific context.
The code reads an arbitrary local video file into memory and sends its contents to a server-side analysis API, but there is no visible user-facing notice, consent step, or data-handling disclosure in this file. Because the skill processes pet-area videos that may contain sensitive household imagery or personal information, silent transmission creates a real privacy and compliance risk even if the transfer is functionally intended.
The function forwards a local file path or remote URL to skill.get_output_analysis(...), which invokes external analysis behavior without any explicit disclosure at the point of use that user-supplied media or references may be sent to a server-side service. In this pet wellness context, videos may contain household interiors, people, and behavioral data, so undisclosed transmission creates privacy and data-handling risk.
This code issues outbound HTTP requests using caller-supplied data such as "tosKey" without any confirmation prompt, logging, comment, or docstring explaining that data will be sent to an external service. The same pattern recurs throughout the file for generic request wrappers, making the network transmission behavior non-obvious from this file alone.
This file exposes broad generic CRUD and arbitrary HTTP wrapper methods that are not constrained to the stated pet-toy interaction analysis purpose. In an agent/skill context, such reusable wrappers can be invoked to contact unexpected endpoints or perform unrelated remote actions, expanding the attack surface and enabling misuse if higher-level inputs are insufficiently validated.
Detected: suspicious.install_untrusted_source