Back to skill

Security audit

Pet Vocal Emotion Analysis Skill | 宠物叫声情绪解析技能

Security checks for vulnerabilities and agentic risk

Overview

The skill is a cloud media-analysis wrapper that silently creates or reuses a persistent user identity and stores tokens, which is too sensitive and under-controlled for a pet voice analysis skill.

Review this skill before installing. It may send pet audio/video or URLs to lifeemergence.com cloud services, create or reuse a persistent local identity, and store authentication tokens in the workspace. Avoid using real phone numbers or personal identifiers unless the publisher clearly documents the account flow, token storage, and deletion controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (57)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The described filesystem access, local identity-file reads, default-user persistence, backend login/provisioning, token refresh, and billing handling greatly exceed the expectations of a pet-emotion skill. These behaviors introduce credential, privacy, and unauthorized account-linkage risks, especially because the skill claims not to require user identity input while silently managing identity state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The described filesystem access, local identity-file reads, default-user persistence, backend login/provisioning, token refresh, and billing handling greatly exceed the expectations of a pet-emotion skill. These behaviors introduce credential, privacy, and unauthorized account-linkage risks, especially because the skill claims not to require user identity input while silently managing identity state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The described filesystem access, local identity-file reads, default-user persistence, backend login/provisioning, token refresh, and billing handling greatly exceed the expectations of a pet-emotion skill. These behaviors introduce credential, privacy, and unauthorized account-linkage risks, especially because the skill claims not to require user identity input while silently managing identity state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described filesystem access, local identity-file reads, default-user persistence, backend login/provisioning, token refresh, and billing handling greatly exceed the expectations of a pet-emotion skill. These behaviors introduce credential, privacy, and unauthorized account-linkage risks, especially because the skill claims not to require user identity input while silently managing identity state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described filesystem access, local identity-file reads, default-user persistence, backend login/provisioning, token refresh, and billing handling greatly exceed the expectations of a pet-emotion skill. These behaviors introduce credential, privacy, and unauthorized account-linkage risks, especially because the skill claims not to require user identity input while silently managing identity state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described filesystem access, local identity-file reads, default-user persistence, backend login/provisioning, token refresh, and billing handling greatly exceed the expectations of a pet-emotion skill. These behaviors introduce credential, privacy, and unauthorized account-linkage risks, especially because the skill claims not to require user identity input while silently managing identity state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described filesystem access, local identity-file reads, default-user persistence, backend login/provisioning, token refresh, and billing handling greatly exceed the expectations of a pet-emotion skill. These behaviors introduce credential, privacy, and unauthorized account-linkage risks, especially because the skill claims not to require user identity input while silently managing identity state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described filesystem access, local identity-file reads, default-user persistence, backend login/provisioning, token refresh, and billing handling greatly exceed the expectations of a pet-emotion skill. These behaviors introduce credential, privacy, and unauthorized account-linkage risks, especially because the skill claims not to require user identity input while silently managing identity state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The described filesystem access, local identity-file reads, default-user persistence, backend login/provisioning, token refresh, and billing handling greatly exceed the expectations of a pet-emotion skill. These behaviors introduce credential, privacy, and unauthorized account-linkage risks, especially because the skill claims not to require user identity input while silently managing identity state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described filesystem access, local identity-file reads, default-user persistence, backend login/provisioning, token refresh, and billing handling greatly exceed the expectations of a pet-emotion skill. These behaviors introduce credential, privacy, and unauthorized account-linkage risks, especially because the skill claims not to require user identity input while silently managing identity state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described filesystem access, local identity-file reads, default-user persistence, backend login/provisioning, token refresh, and billing handling greatly exceed the expectations of a pet-emotion skill. These behaviors introduce credential, privacy, and unauthorized account-linkage risks, especially because the skill claims not to require user identity input while silently managing identity state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described filesystem access, local identity-file reads, default-user persistence, backend login/provisioning, token refresh, and billing handling greatly exceed the expectations of a pet-emotion skill. These behaviors introduce credential, privacy, and unauthorized account-linkage risks, especially because the skill claims not to require user identity input while silently managing identity state.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "pet-vocal-emotion-analysis"
description: "Recognizes cat and dog barks through pet voiceprint AI, translates and outputs emotions and behavioral intentions such as happiness, excitement, anger, anxiety, pain, vigilance, and attention-seeking, enabling human-pet smart interaction. | 宠物叫声情绪解析技能,通过宠物声纹AI识别猫狗叫声,翻译输出开心、兴奋、愤怒、焦虑、痛苦、警惕、求关注等情绪与行为意图,实现人宠智能交互"
version: "1.0.18"
license: "MIT-0"
---

# 🔊 Pet Vocal Emotion Analysis Skill | 宠物叫声情绪解析技能
> **智能分析中枢** · �

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that raw video data is deleted immediately after analysis, yet elsewhere says attachments are automatically saved as local files. This contradiction is dangerous because it misleads users about retention and creates a real risk of sensitive media persisting on disk despite privacy assurances.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatic internal identity association and fallback creation of a local default user are unnecessary and high-risk for a pet-audio analysis feature. Silent identity binding can link analyses across sessions, create unexpected persistent profiles, and expose users to privacy violations or cross-user data mix-ups.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a skill for analyzing cat/dog vocalizations and inferring emotions, but this code accepts a local video path or network video URL, uploads the file as 'videoUrl' or binary file content, and invokes a generic analysis workflow. Nothing in this file indicates pet-audio-specific processing, voiceprint recognition, or emotion translation for animal sounds; instead it appears to drive a broader report-generation service for videos.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation performs generic video analysis and history listing instead of the declared pet vocal emotion analysis. This mismatch is dangerous because it can cause the platform or users to send unintended media and identifiers to a different backend capability than advertised, creating deception, privacy, and unauthorized data-processing risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The user-facing descriptions and argument help explicitly present this as a video analysis tool, directly contradicting the advertised pet-voice emotion skill. Such contradiction increases the likelihood of user deception and accidental collection or processing of unrelated content, especially where users rely on the marketplace description to understand what data will be handled.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file implements a generic network service layer with broad CRUD operations and arbitrary HTTP GET/POST/PUT/DELETE helpers that can call caller-supplied URLs, which is far wider than the declared pet vocal emotion analysis purpose. In an agent-skill context, this expands the attack surface for unintended data access, exfiltration, service abuse, and hidden capability reuse, especially because there is no visible allowlist, authorization guard, or purpose restriction in this wrapper.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module implements persistent user/account management inside a skill advertised as pet vocal emotion analysis. This capability mismatch is dangerous because it expands the skill's data access surface beyond user expectations and suggests hidden collection or tracking functionality unrelated to the declared purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The User model stores identity and authentication-related fields including username, realname, email, token, and open_token, none of which are justified by pet sound emotion analysis. Unnecessary storage of tokens and personal identifiers increases the risk of credential exposure, tracking, and privacy violations if the local database is accessed or mishandled.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This utility provisions and persists user identity state outside the stated pet-vocal-emotion-analysis purpose, including generating default user identifiers, reading identity material from workspace files, and storing a current open-id globally. That creates unnecessary identity coupling and silent account creation/persistence behavior, which can enable tracking, cross-skill correlation, and unauthorized use of backend identity contexts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The HTTP client silently auto-registers/logs in users against remote services, retrieves tokens, and stores them locally for reuse. For a pet-sound emotion skill, this is materially out of scope and dangerous because it performs undisclosed account lifecycle actions and accumulates authentication artifacts that could be abused if the workspace or logs are exposed.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises shell, filesystem, environment, and network-capable behavior through documented script execution, local file saving, and cloud API access, but it does not declare any explicit tool scope or allowed-tools boundary. This weakens policy enforcement and increases the chance that an agent executes higher-risk operations than reviewers or users expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document expands a pet vocal analysis skill into image/video analysis, cloud report retrieval, and local file saving, which materially broadens both data types handled and capabilities used. This scope creep is dangerous because it encourages users to provide more sensitive content than the title and purpose imply.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2