Back to skill

Security audit

Pet Toy Interaction Activity Analysis | 宠物玩具互动活跃度分析

Security checks for vulnerabilities and agentic risk

Overview

The skill’s pet-video cloud analysis purpose is mostly coherent, but it silently creates or reuses an identity and persists service tokens locally, which requires review before installation.

Review this skill before installing. It sends videos or video URLs to lifeemergence.com/open.lifeemergence.com services and may link results to an automatically chosen identity. It can silently create or reuse a service account and store reusable authentication tokens in a local workspace database, so only install it if you accept that identity linkage, local credential persistence, and cloud report history access.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/util.py:423
Finding

Automatic Identity Transmission and Plaintext Authentication Token Storage

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smyx_common/scripts/util.py:445
Finding

Authentication Headers Can Be Disclosed to Arbitrary Absolute URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (51)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Reading a local workspace file for identity/open-id, mutating a user database, auto-registering backend accounts, and managing auth tokens are powerful side effects far outside the declared pet-toy analysis scope. This is dangerous because a user supplying a video or URL could unknowingly trigger identity linkage, account creation, and credential handling, creating privacy, consent, and unauthorized access concerns.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The YARA hit indicates suspicious metadata/manifest characteristics consistent with tool or metadata poisoning patterns. While the matched snippet alone is weak evidence, in the context of multiple description-behavior mismatches and undeclared capabilities, malformed or overloaded metadata increases the risk that the manifest is being used to obscure true behavior or influence tool routing improperly.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-pet-toy-interaction-activity-analysis"
description: "Triggers when a user provides a pet toy area video URL or file for analysis; supports local video uploads or network URLs to call server-side APIs for toy interaction behavior recognition, tracking interaction frequency, duration, and toy preference per pet, generating daily activity curves and trend comparisons to detect declining activity that may indicate illness or depression. Application scenarios: smart pet toys, pet wellness monitoring. | 当用户提供玩具区域视频URL或文件时,触发本技能进行互动行为分析;支持通过上传本地视频或网络视�

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill accepts local files and remote URLs and states that server-side APIs will be called, but it does not clearly warn users that uploaded media or referenced URLs will be transmitted to cloud services. This is a significant privacy and consent issue, especially for user-provided videos that may contain sensitive household, location, or identifying information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code creates and persists synthetic user identities when no user identity is provided, including reading an identity from a workspace file, reusing a locally stored account, or generating a new one and saving it. For a pet toy video analysis skill, this exceeds the stated purpose and silently establishes persistent identity state that can be used to impersonate users or tie activity to undeclared accounts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The HTTP helper automatically triggers phone-login/registration, retrieves tokens, and stores them locally for reuse. That behavior is unrelated to simple pet video analysis and creates hidden account provisioning and session persistence, which can be abused for unauthorized service access or silent account linking.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and instructs use of shell execution, network access, local file reads/writes, and environment-dependent behavior, but it declares no explicit tool scope or permission boundaries. That makes the skill capable of broader operations than a reviewer or runtime policy can easily constrain, increasing the chance of unintended data access or command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad wellness and behavior terms that could activate the skill in unrelated conversations, causing unintended processing of attachments or cloud queries. In a skill that can save local files and call remote APIs, over-triggering increases the chance of accidental data disclosure or execution of undesired workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill metadata says it is triggered to analyze a provided toy-area video URL or file, but the code also exposes a history-listing mode that retrieves prior analysis records by open_id. That expands the data access scope beyond the stated purpose and can enable unauthorized or unexpected access to historical pet activity data if invoked through the agent or CLI.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The argument parser description and help text are presented only in Chinese, and the runtime status/error messages are likewise hard-coded to a single language. This forces a specific language for all users without any documented locale choice or opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code resolves and uses an internal open_id without clear user-facing disclosure, and can optionally take a hidden --open-id parameter. Hidden identity binding increases the risk of processing or exposing another user's historical analysis data without informed consent, especially because the same identity is later used for list retrieval.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Multiple returned status and result strings are fixed in Chinese, which forces a specific language for user-visible interaction. The file does not offer localization, user opt-in, or any justification that the skill is intended only for a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code reads an arbitrary local video file into memory and sends its contents to a server-side analysis API, but there is no visible user-facing notice, consent step, or data-handling disclosure in this file. Because the skill processes pet-area videos that may contain sensitive household imagery or personal information, silent transmission creates a real privacy and compliance risk even if the transfer is functionally intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function forwards a local file path or remote URL to skill.get_output_analysis(...), which invokes external analysis behavior without any explicit disclosure at the point of use that user-supplied media or references may be sent to a server-side service. In this pet wellness context, videos may contain household interiors, people, and behavioral data, so undisclosed transmission creates privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code issues outbound HTTP requests using caller-supplied data such as "tosKey" without any confirmation prompt, logging, comment, or docstring explaining that data will be sent to an external service. The same pattern recurs throughout the file for generic request wrappers, making the network transmission behavior non-obvious from this file alone.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file exposes broad generic CRUD and arbitrary HTTP wrapper methods that are not constrained to the stated pet-toy interaction analysis purpose. In an agent/skill context, such reusable wrappers can be invoked to contact unexpected endpoints or perform unrelated remote actions, expanding the attack surface and enabling misuse if higher-level inputs are insufficiently validated.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2