Back to skill

Security audit

Plant Growth Stage Recognition Skill | 植物生长阶段识别技能

Security checks for vulnerabilities and agentic risk

Overview

The skill does perform cloud plant-media analysis, but it also silently provisions and persists user identity tokens in a local database.

Install only if you are comfortable sending plant images/videos or supplied URLs to the lifeemergence cloud service and with the skill silently creating or reusing a local identity. Review and clear the workspace data database/tokens if you do not want persistent account linkage or history retrieval.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding describes broad filesystem operations, local credential-like file reads, persistent identity creation, outbound HTTP auth flows, token handling, and retries—far beyond the stated purpose of plant-stage recognition. In this skill context, the mismatch is especially dangerous because benign agricultural branding may cause users to authorize sensitive local and network access they would not otherwise permit.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding describes broad filesystem operations, local credential-like file reads, persistent identity creation, outbound HTTP auth flows, token handling, and retries—far beyond the stated purpose of plant-stage recognition. In this skill context, the mismatch is especially dangerous because benign agricultural branding may cause users to authorize sensitive local and network access they would not otherwise permit.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding describes broad filesystem operations, local credential-like file reads, persistent identity creation, outbound HTTP auth flows, token handling, and retries—far beyond the stated purpose of plant-stage recognition. In this skill context, the mismatch is especially dangerous because benign agricultural branding may cause users to authorize sensitive local and network access they would not otherwise permit.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding describes broad filesystem operations, local credential-like file reads, persistent identity creation, outbound HTTP auth flows, token handling, and retries—far beyond the stated purpose of plant-stage recognition. In this skill context, the mismatch is especially dangerous because benign agricultural branding may cause users to authorize sensitive local and network access they would not otherwise permit.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding describes broad filesystem operations, local credential-like file reads, persistent identity creation, outbound HTTP auth flows, token handling, and retries—far beyond the stated purpose of plant-stage recognition. In this skill context, the mismatch is especially dangerous because benign agricultural branding may cause users to authorize sensitive local and network access they would not otherwise permit.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding describes broad filesystem operations, local credential-like file reads, persistent identity creation, outbound HTTP auth flows, token handling, and retries—far beyond the stated purpose of plant-stage recognition. In this skill context, the mismatch is especially dangerous because benign agricultural branding may cause users to authorize sensitive local and network access they would not otherwise permit.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding describes broad filesystem operations, local credential-like file reads, persistent identity creation, outbound HTTP auth flows, token handling, and retries—far beyond the stated purpose of plant-stage recognition. In this skill context, the mismatch is especially dangerous because benign agricultural branding may cause users to authorize sensitive local and network access they would not otherwise permit.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding describes broad filesystem operations, local credential-like file reads, persistent identity creation, outbound HTTP auth flows, token handling, and retries—far beyond the stated purpose of plant-stage recognition. In this skill context, the mismatch is especially dangerous because benign agricultural branding may cause users to authorize sensitive local and network access they would not otherwise permit.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding describes broad filesystem operations, local credential-like file reads, persistent identity creation, outbound HTTP auth flows, token handling, and retries—far beyond the stated purpose of plant-stage recognition. In this skill context, the mismatch is especially dangerous because benign agricultural branding may cause users to authorize sensitive local and network access they would not otherwise permit.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding describes broad filesystem operations, local credential-like file reads, persistent identity creation, outbound HTTP auth flows, token handling, and retries—far beyond the stated purpose of plant-stage recognition. In this skill context, the mismatch is especially dangerous because benign agricultural branding may cause users to authorize sensitive local and network access they would not otherwise permit.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding describes broad filesystem operations, local credential-like file reads, persistent identity creation, outbound HTTP auth flows, token handling, and retries—far beyond the stated purpose of plant-stage recognition. In this skill context, the mismatch is especially dangerous because benign agricultural branding may cause users to authorize sensitive local and network access they would not otherwise permit.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding describes broad filesystem operations, local credential-like file reads, persistent identity creation, outbound HTTP auth flows, token handling, and retries—far beyond the stated purpose of plant-stage recognition. In this skill context, the mismatch is especially dangerous because benign agricultural branding may cause users to authorize sensitive local and network access they would not otherwise permit.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding describes broad filesystem operations, local credential-like file reads, persistent identity creation, outbound HTTP auth flows, token handling, and retries—far beyond the stated purpose of plant-stage recognition. In this skill context, the mismatch is especially dangerous because benign agricultural branding may cause users to authorize sensitive local and network access they would not otherwise permit.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The YARA hit indicates metadata-poisoning characteristics in the manifest/description field. While the evidence here is weaker than the documented behavior mismatches, suspicious or malformed metadata in a skill manifest can be used to mislead tooling, evade review, or manipulate how the skill is classified and trusted.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "plant-growth-stage-recognition-analysis"
description: "Accurately identifies key growth stages of plants from germination to fruiting based on computer vision and deep learning, provides structured data for precision agriculture decision support. | 植物生长阶段识别技能,基于计算机视觉与深度学习算法,精准识别植物从发芽到结果的全生命周期关键生长阶段,为精准农业提供科学决策支持"
version: "1.0.17"
license: "MIT-0"
---

# 🌱 Plant Growth Stage Recognition Skill | 植物生长阶段识别技能
> **智能分析中枢** · 图片/视频智能分析 · 结构化报告 · 历�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation accepts arbitrary local video files or remote video URLs, uploads them to a generic analysis backend, and returns generic report data. That behavior materially differs from the declared plant growth stage recognition purpose, creating a scope-mismatch that can mislead users into sending unrelated sensitive media to a service with broader analysis capabilities.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation does not match the advertised plant growth stage recognition purpose and instead performs generic video analysis/history retrieval through an external skill API. This is dangerous because users, integrators, or automated systems may grant the skill data access and trust based on its stated agricultural function while it actually processes different content and may expose unrelated analysis capabilities or data flows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file defines generic user-account persistence and retrieval logic, including a User model and UserDao, which is materially unrelated to the stated plant growth stage recognition purpose. Capability mismatch is dangerous because hidden identity, account, or persistence features can support covert data collection or broader platform abuse while appearing to be an agriculture CV skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The User model stores profile and credential-adjacent data including username, realname, email, token, and open_token, none of which are justified by a plant growth stage recognition skill. In skill context this is more dangerous because the mismatch suggests unnecessary collection or retention of sensitive identifiers and tokens, increasing the risk of credential leakage, cross-skill tracking, or unauthorized account linkage.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code reads workspace identity material from data/smyx-api-key.txt, falls back to a local database, and can generate persistent default identities automatically. This creates silent credential/identity harvesting and persistence behavior that users of a plant-recognition skill would not reasonably expect, and it may cause requests to be attributed to unintended accounts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The utility layer performs account provisioning, token retrieval, and authenticated backend login behavior that is unrelated to plant growth stage recognition. In a skill expected to do CV-based crop analysis, hidden identity bootstrapping and remote auth flows materially increase risk because invoking the skill can silently enroll users and establish external service access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The request path can create and update local user records as a side effect of ordinary HTTP calls, coupling network access with stateful identity mutation. This is dangerous because a seemingly simple skill invocation can silently persist tokens and user metadata, expanding blast radius if the host workspace or local database is later accessed by another component.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and instructs use of shell execution, local file handling, environment-derived identity, and outbound network access, but does not declare any explicit tool/permission scope. This increases the blast radius because a caller cannot easily constrain what the skill may access, and the hidden capability set is broader than a simple plant-analysis skill would suggest.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The history-report trigger phrases are broad enough that ordinary conversation about reports may auto-invoke cloud history lookup. Because history retrieval is tied to internal identity association, accidental triggering can expose metadata or report links the user did not explicitly request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill does not prominently warn users that uploaded local files and supplied remote URLs are transmitted to a cloud API. This is dangerous because users may assume local-only analysis for plant images/videos and inadvertently disclose sensitive farm, location, or business information to a third party.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The function exposes a history/listing capability (show_analyze_list) that is unrelated to the advertised plant growth stage recognition purpose. Unrelated data-access features increase attack surface and can enable unauthorized enumeration of prior analyses or user-associated records if access control is weak elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2