Back to skill

Security audit

Plant Vitality Index | 植物整体活力指数(综合评分)

Security checks for vulnerabilities and agentic risk

Overview

The skill can perform plant-analysis-style cloud processing, but it silently manages account identity, stores tokens locally, and can fetch account-linked report history, so it should be reviewed before installation.

Install only if you are comfortable with plant images or videos, report history, and an internal account identifier being sent to the Life Emergence cloud service. Review how the platform authenticates open-id values and where the local SQLite token database is stored before using history lookup or shared workspaces.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
skills/smyx_common/scripts/util.py:542
Finding

Caller-Controlled Identity Enables Unauthorized Account Impersonation

Content
View full analysis

Vulnerability Details

File Location: scripts/smyx_plant_vitality_index_analysis.py:45, 60-65; skills/smyx_common/scripts/util.py:458-471, 542-612
Vulnerability Type: Improper authentication and caller-controlled identity impersonation
Risk Level: High

Technical Analysis

The CLI accepts an unrestricted hidden --open-id argument and treats it as a trusted internal identity:

python
parser.add_argument("--open-id", required=False, help=argparse.SUPPRESS)

The supplied value is passed directly into identity initialization:

python
OpenIdUtil.resolve_current_open_id(args.open_id, use_current=bool(args.open_id))

if args.list:
    open_id = ConstantEnum.CURRENT__OPEN_ID
    result = show_analyze_list(open_id)
    print(result)
    exit(0)

resolve_current_open_id performs no authentication or integrity verification before installing that value as the process-wide current identity:

python
@classmethod
def resolve_current_open_id(cls, open_id=None, use_current=True):
    """解析并初始化当前 open-id,返回最终使用值。"""
    resolved_open_id = (open_id or "").strip() if isinstance(open_id, str) else open_id
    if not resolved_open_id and use_current:
        resolved_open_id = ConstantEnum.CURRENT__OPEN_ID or ConstantEnum.CURRENT__USER_NAME
    if not resolved_open_id:
        resolved_open_id = cls.get_api_key_file_open_id()
    if not resolved_open_id:
        resolved_open_id = cls.get_or_create_default_open_id()

    ConstantEnum.CURRENT__OPEN_ID = resolved_open_id
    if not ConstantEnum.CURRENT__USER_NAME:
        ConstantEnum.CURRENT__USER_NAME = resolved_open_id
    return resolved_open_id

The request layer subsequently uses that identity to perform a silent login. It sends the same caller-controlled value as both the Open ID and mobile identifier, without presenting an existing user credential or a cryptographically verified assertion:

python
def _get_or_create_user(username):
    _url = ApiEnum.BASE_URL_HEALTH + "/sys/ph
...[truncated 4006 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove caller-controlled identity selection from the public CLI. Do not accept --open-id as a direct authentication mechanism.
  2. Obtain identities only from a trusted, authenticated upstream context and verify the integrity and issuer of that context before use.
  3. Replace identifier-only silent login with a standard authenticated exchange, such as OAuth, a signed short-lived assertion, or a session token bound to the verified user.
  4. Require the server to reject /sys/phoneLogin requests that provide only an openId or mobile value without proof of ownership.
  5. Enforce report ownership and tenant authorization server-side for every list, detail, export, and analysis endpoint; do not rely solely on client-supplied pnaUserName.
  6. Bind issued tokens to the verified identity, intended client, tenant, and minimum required scopes.
  7. Avoid persisting returned tokens in plaintext where possible. Use an operating-system credential store or encrypted storage with restrictive file permissions.
  8. Add negative authorization tests confirming that one caller cannot select another user's identifier and retrieve that user's reports.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (55)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill appears to perform authenticated external API requests, local file operations, workspace detection, and user identity/token persistence while claiming only plant-vitality scoring. This is dangerous because it combines sensitive identity handling with file/network access under a misleadingly narrow description, increasing risk of unauthorized data exposure and overprivileged execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill appears to perform authenticated external API requests, local file operations, workspace detection, and user identity/token persistence while claiming only plant-vitality scoring. This is dangerous because it combines sensitive identity handling with file/network access under a misleadingly narrow description, increasing risk of unauthorized data exposure and overprivileged execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill appears to perform authenticated external API requests, local file operations, workspace detection, and user identity/token persistence while claiming only plant-vitality scoring. This is dangerous because it combines sensitive identity handling with file/network access under a misleadingly narrow description, increasing risk of unauthorized data exposure and overprivileged execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill appears to perform authenticated external API requests, local file operations, workspace detection, and user identity/token persistence while claiming only plant-vitality scoring. This is dangerous because it combines sensitive identity handling with file/network access under a misleadingly narrow description, increasing risk of unauthorized data exposure and overprivileged execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated external API requests, local file operations, workspace detection, and user identity/token persistence while claiming only plant-vitality scoring. This is dangerous because it combines sensitive identity handling with file/network access under a misleadingly narrow description, increasing risk of unauthorized data exposure and overprivileged execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated external API requests, local file operations, workspace detection, and user identity/token persistence while claiming only plant-vitality scoring. This is dangerous because it combines sensitive identity handling with file/network access under a misleadingly narrow description, increasing risk of unauthorized data exposure and overprivileged execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated external API requests, local file operations, workspace detection, and user identity/token persistence while claiming only plant-vitality scoring. This is dangerous because it combines sensitive identity handling with file/network access under a misleadingly narrow description, increasing risk of unauthorized data exposure and overprivileged execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated external API requests, local file operations, workspace detection, and user identity/token persistence while claiming only plant-vitality scoring. This is dangerous because it combines sensitive identity handling with file/network access under a misleadingly narrow description, increasing risk of unauthorized data exposure and overprivileged execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated external API requests, local file operations, workspace detection, and user identity/token persistence while claiming only plant-vitality scoring. This is dangerous because it combines sensitive identity handling with file/network access under a misleadingly narrow description, increasing risk of unauthorized data exposure and overprivileged execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated external API requests, local file operations, workspace detection, and user identity/token persistence while claiming only plant-vitality scoring. This is dangerous because it combines sensitive identity handling with file/network access under a misleadingly narrow description, increasing risk of unauthorized data exposure and overprivileged execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated external API requests, local file operations, workspace detection, and user identity/token persistence while claiming only plant-vitality scoring. This is dangerous because it combines sensitive identity handling with file/network access under a misleadingly narrow description, increasing risk of unauthorized data exposure and overprivileged execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform authenticated external API requests, local file operations, workspace detection, and user identity/token persistence while claiming only plant-vitality scoring. This is dangerous because it combines sensitive identity handling with file/network access under a misleadingly narrow description, increasing risk of unauthorized data exposure and overprivileged execution.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-plant-vitality-index-analysis"
description: "Using a plant-monitoring platform that periodically (e.g., daily) collects plant images, environmental data, and growth metrics (new bud count, leaf-area change, leaf color), an AI evaluation model fuses leaf color (chlorophyll index), morphology (spread, leaf size), and growth dynamics (new buds, leaf-area growth rate) to output an overall vitality score from 0-100 along with a trend (rising / stable / declining). | 通过植物监测平台定期(如每天)采集的植物图像、环境数据以及生长指标(如新芽数、叶片面积变化、叶色),利用AI综合�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes analysis of plant images, environmental data, and growth metrics to produce a vitality score and trend. This code explicitly requires a local video path or network video URL, validates supported video/file formats, and uploads a file as 'videoUrl' or binary content, which does not match the described plant-vitality scoring workflow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The implementation materially contradicts the declared skill purpose: it exposes a video-analysis and history-listing workflow instead of plant vitality scoring. This kind of capability mismatch is dangerous because users and orchestrators may grant permissions, supply data, or trust outputs based on the manifest, while the code performs unrelated processing and may route different data to backend services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code can generate default open-id values and create/persist user records when no identity is supplied. For a plant analysis skill, silently creating or registering identities is unjustified and dangerous because it can enroll users in backend systems without informed consent, creating privacy, billing, and attribution risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility code performs authenticated remote API access, token management, local user lookup, and account bootstrap behavior that is unrelated to a plant vitality scoring skill's declared purpose. In context, this creates hidden side effects and expands the trust boundary: using the skill may silently contact external services, attach identity material, and persist account state without clear necessity or disclosure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares no explicit tool scope or allowed-tools despite documented behaviors that require shell execution, network access, file read/write, and environment use. In an agent setting, missing capability boundaries increases the chance the skill can invoke broader privileges than users expect, especially since it also directs execution of local scripts and remote API access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation expands the skill from simple scoring into history-querying, report generation, alerting, report-link output, and automatic file saving. This scope inflation matters because users may invoke the skill for low-risk analysis without realizing it stores files or accesses/reporting data remotely.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L030 explicitly instructs that the skill should 'only output score and trend' and 'not provide specific care operations.' This conflicts with other documented behavior that it 'guides care decisions' (L023-L025) and outputs '建议'/'suggestions' as part of results (L020, L130), creating a direct intent-documentation contradiction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default trigger is broad enough to activate whenever a user provides nearly any plant image or video for analysis. Overbroad auto-triggering is risky in agent systems because it can cause unintended script execution, remote uploads, or file handling without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The history-query feature uses broad natural-language phrases and automatic activation, which can cause inadvertent access to prior reports tied to an internal identity. In context, this is more dangerous because the skill also emphasizes silent identity handling and mandatory cloud queries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs automatic local saving of uploaded files without clearly warning users about storage, retention, or location. Saving user-provided media by default creates avoidable privacy and disk exposure risks, especially for images or videos that may contain sensitive surroundings or metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation mandates direct cloud API queries for historical reports but does not clearly warn users that report data will be fetched from a remote service. This can lead to unanticipated transmission and retrieval of account-linked data, particularly because identity association is handled silently.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill claims to analyze plant images and growth indicators to produce a plant vitality score, yet the core function is named analyze_video and mutates ConstantEnum.DEFAULT__PET_TYPE based on a pet_type argument before calling a generic analysis method. This indicates the code is repurposed from a pet-analysis workflow rather than a plant-specific vitality implementation described in the manifest.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2