Back to skill

Security audit

Plant Night Respiration Rate Analysis | 植物夜间呼吸作用强度估算

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it needs Review because it automatically creates or reuses an identity, stores tokens locally, and sends media and credentials to remote services, including an active plaintext development endpoint.

Before installing, confirm you trust the publisher and remote service, require production HTTPS endpoints, and be comfortable with uploaded media/URLs, report history, generated identity values, and access tokens being sent to and stored for that service. Avoid use until the dev HTTP config, dependency name, URL validation, and explicit consent around identity/history access are fixed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/config-dev.yaml:2
Finding

Authentication Data and User Media May Be Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smyx_analysis/scripts/skill.py:113
Finding

Unrestricted Remote Media URL Creates a Server-Side Request Forgery Input Channel

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skills/smyx_analysis/requirements.txt:3
Finding

Noncanonical YAML Dependency Name Introduces Dependency-Confusion Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (62)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated outbound requests, automatic account creation/login, token retrieval, local token/open-id storage, and local database access despite presenting as a plant-analysis tool. This is highly sensitive because it combines identity, authentication, persistence, and external transmission without clear disclosure or narrow scoping.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
88% confidence
Finding

The manifest triggers a metadata-poisoning rule and is consistent with suspicious or malformed description content in a high-trust control surface. Poisoned metadata can manipulate tool selection, evade scanners, or conceal true behavior, and is more dangerous here because the skill already shows significant description/behavior mismatch.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-plant-night-respiration-rate-analysis"
description: "In a plant factory, a fixed thermal imaging camera continuously captures thermal images of the plant canopy leaves at night (no-light period), analyzes leaf temperature trends (respiration releases heat, causing leaf temperature to be slightly higher than air temperature), and combined with optional ambient CO₂ sensor data (respiration releases CO₂ raising concentration), an AI model estimates the relative respiration. | 通过植物工厂内的固定热成像摄像头,在夜间(无光照时段)连续采集植物冠层叶片的热图像,分析叶片温度变化趋势�

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill silently reuses or creates a local default user identity even though its apparent purpose is only media analysis. Silent identity creation and reuse can link actions across sessions, access historical records, and create hidden persistence without user awareness or consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation materially diverges from the declared skill purpose: instead of a constrained plant-respiration analysis flow, it exposes a generic video analysis and history-listing interface. This mismatch is dangerous because users, reviewers, and policy gates may trust the benign agricultural description while the code processes arbitrary local paths or URLs and accesses prior analysis data, increasing the risk of covert data exfiltration, unauthorized content processing, or scope bypass.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This shared utility file contains broad identity management, workspace inspection, credential handling, local persistence, and generic authenticated API capabilities that materially exceed the declared plant-respiration analysis purpose. In a narrowly scoped analytics skill, this kind of overprivileged support code increases the attack surface and enables undisclosed account bootstrapping and outbound service interaction unrelated to the user’s expected task.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code can automatically create or log into users against a remote health service, obtain tokens, and persist them locally, even though that behavior is not justified by nighttime plant thermal analysis. This creates a hidden identity and authentication workflow that could transmit user-linked identifiers off-box and establish durable credentials without clear user awareness.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
81% confidence
Finding

The manifest contains mixed-script and suspicious Unicode content, which can be used to obscure metadata, alter how text is displayed, or hide malicious instructions from reviewers and downstream tooling. In a skill manifest, this is risky because parsers, scanners, and humans may interpret the content differently, reducing review reliability.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill appears to require shell, filesystem, environment, and network capabilities but does not declare an explicit tool scope or permission boundary. This creates hidden privilege and data-flow risk because the agent may invoke powerful operations not visible to users or policy enforcement, including local file access and outbound requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The default trigger is broad enough to activate on nearly any uploaded nighttime plant-related image or video, increasing the chance of accidental execution and unnecessary data transmission. Over-broad auto-invocation is risky when the skill also has network, file, and history-related behaviors.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill includes cloud historical-report querying that is not central to the stated analysis purpose and can expose account-linked prior records. Bundling history access into an analysis skill increases the chance of unintended data disclosure, especially with automatic triggering based on natural-language phrases.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The history-query auto-trigger relies on broad natural-language phrases that may overlap with ordinary requests, causing unintended access to prior cloud records. This is particularly sensitive because history access is identity-linked and not clearly separated from the analysis workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation does not clearly warn users that uploaded files, URLs, and resulting analysis data may be sent to remote APIs and cloud services. This undermines informed consent and can lead to privacy, confidentiality, and regulatory issues if sensitive media or metadata is transmitted externally.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes a specific workflow involving nighttime thermal canopy imagery and optional ambient CO₂ sensor data, but the code merely passes input_path/url into skill.get_output_analysis and lists prior outputs via skill.get_output_analysis_list. There is no evidence in this file of CO₂ input support, thermal-specific validation, or respiration-oriented processing corresponding to the detailed manifest description.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2