T09 · Insecure Skill Coding Practices
- Location
skills/smyx_common/scripts/config.yaml:4- Finding
Development Configuration Forces Sensitive API Traffic over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to provide cloud-based plant media analysis, but it silently manages account identity and stores/reuses tokens while the distributed config can send API traffic over plaintext development HTTP endpoints despite claiming HTTPS.
Review before installing. This skill sends user media and account-scoped report requests to external services, silently creates or reuses an internal identity, and may store reusable tokens locally. The distributed configuration should be corrected to use HTTPS production endpoints only, and users should get clearer controls for identity, history lookup, local retention, and credential deletion.
skills/smyx_common/scripts/config.yaml:4Development Configuration Forces Sensitive API Traffic over Plaintext HTTP
skills/smyx_common/scripts/util.py:571Authenticated Request Helper Can Forward Credentials to Arbitrary Absolute URLs
skills/smyx_common/scripts/dao.py:450Reusable Authentication Tokens Are Stored Unencrypted in a Workspace SQLite Database
The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.
The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.
The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.
The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.
The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.
The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.
The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.
The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.
The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.
The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.
The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.
The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.
The reported use of authenticated external API calls, account/open-id initialization, local token lookup, and persistence integration is much broader than the declared analytical purpose. In this context, hidden identity linkage and external requests raise significant privacy and unauthorized data-access concerns, especially because the skill tells the system to auto-handle identity silently.
The YARA hit for metadata poisoning indicates suspicious manifest text or hidden/invisible characters in tool metadata, which can be used to manipulate parsers, reviewers, or downstream agents. In a skill manifest, poisoned metadata is especially concerning because it can alter how the skill is classified, trusted, or invoked while appearing innocuous to humans.
---
name: "plant-disease-recognition-analysis"
description: "Accurately identifies plant diseases based on computer vision and deep learning, supports both image and video input, outputs structured diagnostic reports including disease type, cause and prevention suggestions. | 植物病害识别技能,基于计算机视觉与深度学习,支持视频/图片输入,精准识别植物病害类型,输出包含病害名称、致病原因、防治建议的结构化诊断报告,为农业生产和园艺养护提供病害预警"
version: "1.0.14"
license: "MIT-0"
---
# 🍃 Plant Disease Recognition Skill | 植物病害识别技能
> **�
The manifest describes a plant disease recognition skill that supports both images and videos and produces structured reports with disease type, causes, and prevention suggestions. This file instead exposes a generic 'video analysis' flow and a history-listing feature, with no image handling, no plant/disease-specific logic, and no evidence of structured diagnostic report generation.
This file implements a generic API wrapper with broad CRUD methods and arbitrary HTTP verbs that are not constrained to plant disease recognition workflows. In an agent skill context, this unnecessarily expands the skill's capability surface, enabling unrelated outbound requests or data operations if other components can pass attacker-controlled URLs or payloads.
The model stores user identity data and authentication-related token fields (token, open_token) in a local SQLite database without any visible encryption, access control, retention policy, or clear need tied to plant disease analysis. If the workspace or database is exposed, these credentials and PII could be harvested and reused for account compromise or tracking.
The file implements a generic ai_chat(prompt, session_id, timeout) capability unrelated to the declared plant-disease-recognition purpose. Even though the subprocess invocation is currently commented out, this scaffolding enables broad prompt-driven agent behavior and creates a dangerous mismatch between the manifest and actual capability, which can be used to smuggle general-purpose agent access into a narrowly scoped skill.
The skill reads local identity artifacts from the workspace and creates fallback user identities when none are present. For a plant disease recognition skill, this is unjustified access to identity state and can lead to silent user impersonation, account proliferation, or linkage of skill actions to unintended identities.
This utility performs remote account provisioning, login bootstrap, token retrieval, token caching, and retry logic that are unrelated to plant disease recognition. In the stated skill context, this is dangerous because invoking the skill can silently create or reuse identities and transmit authentication material to external services without clear necessity or user consent.
The skill advertises and instructs use of shell, network, local file save, and environment-driven behavior, but it does not declare any explicit tool scope or permissions boundaries. In an agent ecosystem, missing scope metadata increases the chance that the skill is granted broader capabilities than users or orchestrators expect, enabling unintended file access, command execution, or outbound requests.
The skill metadata and operational text present the skill name and instructions primarily in Chinese, with no statement that users may choose their preferred language for interaction or outputs. Under the stated policy, a fixed language or locale should either be optional for the user or explicitly justified as region-specific.
The auto-trigger phrases for historical report queries are broad enough that normal conversation about reports could invoke cloud retrieval unexpectedly. In this skill, unintended activation is more dangerous because report listing is tied to internally managed identity and cloud data access, not just local formatting.
The skill states that uploaded files are automatically saved locally, but the documentation does not clearly warn users about local persistence duration, location, or cleanup. Since the inputs are user media and may contain sensitive environmental or identifying information, silent local storage increases privacy and data-retention risk.
The script silently resolves an internal user identity via OpenIdUtil.resolve_current_open_id without clearly disclosing that identity derivation will occur, even when the user did not explicitly provide an open ID. In a CLI that processes user-supplied media and can list prior analyses, hidden identity binding can cause privacy violations, cross-user data access, or unexpected attribution of requests and stored results.
Detected: suspicious.install_untrusted_source