T09 · Insecure Skill Coding Practices
- Location
skills/smyx_common/scripts/config-dev.yaml:2- Finding
Authentication Data and User Media May Be Transmitted over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is not clearly malicious, but it needs Review because it automatically creates or reuses an identity, stores tokens locally, and sends media and credentials to remote services, including an active plaintext development endpoint.
Before installing, confirm you trust the publisher and remote service, require production HTTPS endpoints, and be comfortable with uploaded media/URLs, report history, generated identity values, and access tokens being sent to and stored for that service. Avoid use until the dev HTTP config, dependency name, URL validation, and explicit consent around identity/history access are fixed.
skills/smyx_common/scripts/config-dev.yaml:2Authentication Data and User Media May Be Transmitted over Plaintext HTTP
skills/smyx_analysis/scripts/skill.py:113Unrestricted Remote Media URL Creates a Server-Side Request Forgery Input Channel
skills/smyx_analysis/requirements.txt:3Noncanonical YAML Dependency Name Introduces Dependency-Confusion Risk
The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.
The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.
The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.
The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.
The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.
The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.
The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.
The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.
The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.
The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.
The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.
The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.
The manifest triggers a metadata-poisoning rule and is consistent with suspicious or malformed description content in a high-trust control surface. Poisoned metadata can manipulate tool selection, evade scanners, or conceal true behavior, and is more dangerous here because the skill already shows significant description/behavior mismatch.
---
name: "smyx-plant-night-respiration-rate-analysis"
description: "In a plant factory, a fixed thermal imaging camera continuously captures thermal images of the plant canopy leaves at night (no-light period), analyzes leaf temperature trends (respiration releases heat, causing leaf temperature to be slightly higher than air temperature), and combined with optional ambient CO₂ sensor data (respiration releases CO₂ raising concentration), an AI model estimates the relative respiration. | 通过植物工厂内的固定热成像摄像头,在夜间(无光照时段)连续采集植物冠层叶片的热图像,分析叶片温度变化趋势�
The skill silently reuses or creates a local default user identity even though its apparent purpose is only media analysis. Silent identity creation and reuse can link actions across sessions, access historical records, and create hidden persistence without user awareness or consent.
The implementation materially diverges from the declared skill purpose: instead of a constrained plant-respiration analysis flow, it exposes a generic video analysis and history-listing interface. This mismatch is dangerous because users, reviewers, and policy gates may trust the benign agricultural description while the code processes arbitrary local paths or URLs and accesses prior analysis data, increasing the risk of covert data exfiltration, unauthorized content processing, or scope bypass.
This shared utility file contains broad identity management, workspace inspection, credential handling, local persistence, and generic authenticated API capabilities that materially exceed the declared plant-respiration analysis purpose. In a narrowly scoped analytics skill, this kind of overprivileged support code increases the attack surface and enables undisclosed account bootstrapping and outbound service interaction unrelated to the user’s expected task.
The code can automatically create or log into users against a remote health service, obtain tokens, and persist them locally, even though that behavior is not justified by nighttime plant thermal analysis. This creates a hidden identity and authentication workflow that could transmit user-linked identifiers off-box and establish durable credentials without clear user awareness.
The manifest contains mixed-script and suspicious Unicode content, which can be used to obscure metadata, alter how text is displayed, or hide malicious instructions from reviewers and downstream tooling. In a skill manifest, this is risky because parsers, scanners, and humans may interpret the content differently, reducing review reliability.
The skill appears to require shell, filesystem, environment, and network capabilities but does not declare an explicit tool scope or permission boundary. This creates hidden privilege and data-flow risk because the agent may invoke powerful operations not visible to users or policy enforcement, including local file access and outbound requests.
The default trigger is broad enough to activate on nearly any uploaded nighttime plant-related image or video, increasing the chance of accidental execution and unnecessary data transmission. Over-broad auto-invocation is risky when the skill also has network, file, and history-related behaviors.
The skill includes cloud historical-report querying that is not central to the stated analysis purpose and can expose account-linked prior records. Bundling history access into an analysis skill increases the chance of unintended data disclosure, especially with automatic triggering based on natural-language phrases.
The history-query auto-trigger relies on broad natural-language phrases that may overlap with ordinary requests, causing unintended access to prior cloud records. This is particularly sensitive because history access is identity-linked and not clearly separated from the analysis workflow.
The documentation does not clearly warn users that uploaded files, URLs, and resulting analysis data may be sent to remote APIs and cloud services. This undermines informed consent and can lead to privacy, confidentiality, and regulatory issues if sensitive media or metadata is transmitted externally.
Suspicious Unicode normalization or mixed-script content
The manifest describes a specific workflow involving nighttime thermal canopy imagery and optional ambient CO₂ sensor data, but the code merely passes input_path/url into skill.get_output_analysis and lists prior outputs via skill.get_output_analysis_list. There is no evidence in this file of CO₂ input support, thermal-specific validation, or respiration-oriented processing corresponding to the detailed manifest description.
Detected: suspicious.install_untrusted_source