Back to skill

Security audit

Plant Disease Recognition Skill | 植物病害识别技能

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to provide cloud-based plant media analysis, but it silently manages account identity and stores/reuses tokens while the distributed config can send API traffic over plaintext development HTTP endpoints despite claiming HTTPS.

Review before installing. This skill sends user media and account-scoped report requests to external services, silently creates or reuses an internal identity, and may store reusable tokens locally. The distributed configuration should be corrected to use HTTPS production endpoints only, and users should get clearer controls for identity, history lookup, local retention, and credential deletion.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/config.yaml:4
Finding

Development Configuration Forces Sensitive API Traffic over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smyx_common/scripts/util.py:571
Finding

Authenticated Request Helper Can Forward Credentials to Arbitrary Absolute URLs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smyx_common/scripts/dao.py:450
Finding

Reusable Authentication Tokens Are Stored Unencrypted in a Workspace SQLite Database

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (61)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The YARA hit for metadata poisoning indicates suspicious manifest text or hidden/invisible characters in tool metadata, which can be used to manipulate parsers, reviewers, or downstream agents. In a skill manifest, poisoned metadata is especially concerning because it can alter how the skill is classified, trusted, or invoked while appearing innocuous to humans.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "plant-disease-recognition-analysis"
description: "Accurately identifies plant diseases based on computer vision and deep learning, supports both image and video input, outputs structured diagnostic reports including disease type, cause and prevention suggestions. | 植物病害识别技能,基于计算机视觉与深度学习,支持视频/图片输入,精准识别植物病害类型,输出包含病害名称、致病原因、防治建议的结构化诊断报告,为农业生产和园艺养护提供病害预警"
version: "1.0.14"
license: "MIT-0"
---

# 🍃 Plant Disease Recognition Skill | 植物病害识别技能
> **�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a plant disease recognition skill that supports both images and videos and produces structured reports with disease type, causes, and prevention suggestions. This file instead exposes a generic 'video analysis' flow and a history-listing feature, with no image handling, no plant/disease-specific logic, and no evidence of structured diagnostic report generation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file implements a generic API wrapper with broad CRUD methods and arbitrary HTTP verbs that are not constrained to plant disease recognition workflows. In an agent skill context, this unnecessarily expands the skill's capability surface, enabling unrelated outbound requests or data operations if other components can pass attacker-controlled URLs or payloads.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
91% confidence
Finding

The model stores user identity data and authentication-related token fields (token, open_token) in a local SQLite database without any visible encryption, access control, retention policy, or clear need tied to plant disease analysis. If the workspace or database is exposed, these credentials and PII could be harvested and reused for account compromise or tracking.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file implements a generic ai_chat(prompt, session_id, timeout) capability unrelated to the declared plant-disease-recognition purpose. Even though the subprocess invocation is currently commented out, this scaffolding enables broad prompt-driven agent behavior and creates a dangerous mismatch between the manifest and actual capability, which can be used to smuggle general-purpose agent access into a narrowly scoped skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill reads local identity artifacts from the workspace and creates fallback user identities when none are present. For a plant disease recognition skill, this is unjustified access to identity state and can lead to silent user impersonation, account proliferation, or linkage of skill actions to unintended identities.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility performs remote account provisioning, login bootstrap, token retrieval, token caching, and retry logic that are unrelated to plant disease recognition. In the stated skill context, this is dangerous because invoking the skill can silently create or reuse identities and transmit authentication material to external services without clear necessity or user consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises and instructs use of shell, network, local file save, and environment-driven behavior, but it does not declare any explicit tool scope or permissions boundaries. In an agent ecosystem, missing scope metadata increases the chance that the skill is granted broader capabilities than users or orchestrators expect, enabling unintended file access, command execution, or outbound requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill metadata and operational text present the skill name and instructions primarily in Chinese, with no statement that users may choose their preferred language for interaction or outputs. Under the stated policy, a fixed language or locale should either be optional for the user or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The auto-trigger phrases for historical report queries are broad enough that normal conversation about reports could invoke cloud retrieval unexpectedly. In this skill, unintended activation is more dangerous because report listing is tied to internally managed identity and cloud data access, not just local formatting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that uploaded files are automatically saved locally, but the documentation does not clearly warn users about local persistence duration, location, or cleanup. Since the inputs are user media and may contain sensitive environmental or identifying information, silent local storage increases privacy and data-retention risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script silently resolves an internal user identity via OpenIdUtil.resolve_current_open_id without clearly disclosing that identity derivation will occur, even when the user did not explicitly provide an open ID. In a CLI that processes user-supplied media and can list prior analyses, hidden identity binding can cause privacy violations, cross-user data access, or unexpected attribution of requests and stored results.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2