Back to skill

Security audit

Pet Social Interaction Analysis | 宠物社交行为分析(与其他宠物互动)

Security checks for vulnerabilities and agentic risk

Overview

This skill’s pet-video analysis purpose is plausible, but it silently links identity, stores tokens, and can send private media and credentials over insecure default HTTP endpoints.

Install only if you are comfortable with private pet or household camera media being sent to a cloud service, report history being tied to an automatically selected identity, and tokens being stored in the workspace. The publisher should switch defaults to HTTPS production endpoints, require explicit consent for upload/history/account registration, and avoid persisting reusable tokens in a shared local database.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/config-dev.yaml:2
Finding

Authentication Credentials and Private Video Data Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smyx_common/scripts/util.py:554
Finding

Silent Collection, Remote Registration, and Local Persistence of User Identity and Tokens

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (56)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to generate and persist default identities, access local user databases, update tokens, and perform network authentication despite being described as simple pet-behavior analysis. In context, this is especially dangerous because the skill handles household camera media, so undisclosed identity binding and cloud transmission can expose sensitive personal and behavioral data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to generate and persist default identities, access local user databases, update tokens, and perform network authentication despite being described as simple pet-behavior analysis. In context, this is especially dangerous because the skill handles household camera media, so undisclosed identity binding and cloud transmission can expose sensitive personal and behavioral data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to generate and persist default identities, access local user databases, update tokens, and perform network authentication despite being described as simple pet-behavior analysis. In context, this is especially dangerous because the skill handles household camera media, so undisclosed identity binding and cloud transmission can expose sensitive personal and behavioral data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to generate and persist default identities, access local user databases, update tokens, and perform network authentication despite being described as simple pet-behavior analysis. In context, this is especially dangerous because the skill handles household camera media, so undisclosed identity binding and cloud transmission can expose sensitive personal and behavioral data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to generate and persist default identities, access local user databases, update tokens, and perform network authentication despite being described as simple pet-behavior analysis. In context, this is especially dangerous because the skill handles household camera media, so undisclosed identity binding and cloud transmission can expose sensitive personal and behavioral data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to generate and persist default identities, access local user databases, update tokens, and perform network authentication despite being described as simple pet-behavior analysis. In context, this is especially dangerous because the skill handles household camera media, so undisclosed identity binding and cloud transmission can expose sensitive personal and behavioral data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to generate and persist default identities, access local user databases, update tokens, and perform network authentication despite being described as simple pet-behavior analysis. In context, this is especially dangerous because the skill handles household camera media, so undisclosed identity binding and cloud transmission can expose sensitive personal and behavioral data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to generate and persist default identities, access local user databases, update tokens, and perform network authentication despite being described as simple pet-behavior analysis. In context, this is especially dangerous because the skill handles household camera media, so undisclosed identity binding and cloud transmission can expose sensitive personal and behavioral data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to generate and persist default identities, access local user databases, update tokens, and perform network authentication despite being described as simple pet-behavior analysis. In context, this is especially dangerous because the skill handles household camera media, so undisclosed identity binding and cloud transmission can expose sensitive personal and behavioral data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to generate and persist default identities, access local user databases, update tokens, and perform network authentication despite being described as simple pet-behavior analysis. In context, this is especially dangerous because the skill handles household camera media, so undisclosed identity binding and cloud transmission can expose sensitive personal and behavioral data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to generate and persist default identities, access local user databases, update tokens, and perform network authentication despite being described as simple pet-behavior analysis. In context, this is especially dangerous because the skill handles household camera media, so undisclosed identity binding and cloud transmission can expose sensitive personal and behavioral data.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-social-interaction-analysis-analysis"
description: "AI-powered pet social interaction analysis for multi-pet households. Uses pose recognition and behavior classification to detect cat-cat, dog-dog, and cat-dog interactions—sniffing, chasing, biting, fleeing, hiding, playing—then records duration, frequency, initiator and receiver to generate a social-behavior report. Helps owners understand pet relationships, spot aggression or stress sources, and promote harmonious cohabitation. Scenarios: multi-pet homes, pet boarding centers, pet daycare, animal behavior clinics. | 通过多宠家庭固定摄像头,分析宠物之间(�

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill accepts household pet images/videos and performs cloud-based analysis and history storage, yet the description does not clearly warn users that media and report data may be transmitted to and stored by external services. This is dangerous because in-home camera footage is highly sensitive and may reveal people, interiors, routines, and account-linked behavioral history.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The _get_or_create_user flow sends a phoneLogin/register request with silent registration enabled, using the username/openId as both identifier and mobile value. Automatically creating remote accounts unrelated to the advertised pet-analysis function is dangerous because it can register or link identities without informed consent and expose users to unexpected backend account creation and tracking.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares broad operational behavior that implies shell, filesystem, network, and environment access, but it does not define any explicit tool scope or permission boundaries. In an agent environment, this increases the chance of unintended privileged execution and makes review and containment of the skill much harder.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L030 says the skill should 'not provide medical or training advice, only output visual behavior observation results.' However, elsewhere the skill's documented outputs and sample report content include '建议' and concrete intervention recommendations such as isolation, adding resources, and seeking behavior consultation. This is a semantic mismatch between the claimed limited observation-only role and the broader advisory behavior described in the skill file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The AI role at L030 explicitly says 'Do not provide medical or training advice, only output visual behavior observation results.' But L020 lists '建议与报告链接' as an output capability, and L173-L188 contain explicit recommendation tables and escalation advice. This is an active contradiction within the skill's own documentation about intended behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

An overly broad default auto-trigger can cause the skill to activate on loosely related user inputs and process attachments automatically. In this skill's context, that is more dangerous because inputs can include local files and URLs, potentially causing unneeded media upload, file handling, or remote API calls without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Broad history-query triggers can automatically invoke cloud record retrieval on vague phrases, which risks exposing prior report metadata or links without a sufficiently clear request. Because the skill also auto-associates internal identity, this creates a meaningful privacy risk if the wrong conversation context triggers a lookup.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The string returned at L17 is a fixed Chinese-language heading, which imposes a specific language on all users without any visible opt-in or locale-selection mechanism in this file. This matches the policy category for language or locale constraints that are not optional or clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script silently resolves an internal user identity via OpenIdUtil.resolve_current_open_id() without clear user disclosure, even though the identifier affects access to per-user analysis history and backend behavior. Hidden identity binding can cause privacy violations, accidental cross-account data access, or unexpected attribution of uploaded/queried pet-behavior data, especially in shared environments or automated agent contexts.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes analysis of video from fixed cameras in multi-pet environments, which implies analyzing provided pet-interaction footage, but does not mention ingesting arbitrary network-hosted videos by URL. The code explicitly supports HTTP/HTTPS input via videoUrl, broadening the skill from local/video-upload analysis to general remote URL retrieval and analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

User-supplied remote video URLs are forwarded to the backend service without any visible notice that the external URL will be shared for processing. This creates a privacy and transparency issue, and depending on backend behavior may also cause the service to retrieve unexpected or sensitive resources supplied by the user.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2