Back to skill

Security audit

Outdoor Sports Event Risk Analysis Tool | 户外体育赛事风险分析工具

Security checks for vulnerabilities and agentic risk

Overview

This sports video analysis skill is not clearly malicious, but it silently creates and reuses cloud identity state while sending sensitive media and report queries to remote services, which needs Review before install.

Install only if users understand that videos, video URLs, identity fields, and report-history queries go to the configured lifeemergence cloud services. Avoid use in shared workspaces unless every invocation has a trusted per-user identity; otherwise reports can be tied to a reused local default user. The publisher should add explicit privacy/retention disclosure, confirmation before history lookup, and reject history queries when no authenticated per-user identity is available.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/sport_analysis.py:199
Finding

Shared Fallback Identity Allows Cross-User Report Access

Content
View full analysis

Vulnerability Details

File Location: scripts/sport_analysis.py:199-204; skills/smyx_common/scripts/util.py:428-469; skills/smyx_common/scripts/util.py:619-623
Vulnerability Type: Broken user isolation through shared fallback identity
Risk Level: High

Vulnerable Code

scripts/sport_analysis.py:199-204:

python
# Initialize the internal user identity.
OpenIdUtil.resolve_current_open_id(args.open_id, use_current=bool(args.open_id))

if args.list:
    open_id = ConstantEnum.CURRENT__OPEN_ID
    result = show_analyze_list(open_id)
    print(result)
    exit(0)

skills/smyx_common/scripts/util.py:428-469:

python
@classmethod
def get_or_create_default_open_id(cls):
    from .dao import UserDao, User
    import uuid

    user_dao = UserDao()
    user = user_dao.get_first_default_user(
        cls.DEFAULT_PREFIX,
        cls.DEFAULT_USERNAME_LENGTH
    )
    if user and user.username:
        return user.username

    for _ in range(10):
        username = cls.generate_default_open_id()
        if user_dao.get_by_username(username):
            continue
        now = datetime.now()
        user = User(
            id=uuid.uuid4().hex,
            username=username,
            realname=username,
            source=ConstantEnum.APP__SOURCE,
            del_flag=0,
            create_time=now,
            update_time=now
        )
        user_dao.add(user)
        return username

    raise RuntimeError(
        "Failed to generate a default open-id after repeated collisions"
    )

@classmethod
def resolve_current_open_id(cls, open_id=None, use_current=True):
    resolved_open_id = (
        (open_id or "").strip()
        if isinstance(open_id, str)
        else open_id
    )
    if not resolved_open_id and use_current:
        resolved_open_id = (
            ConstantEnum.CURRENT__OPEN_ID
            or ConstantEnum.CURRENT__USER_NAME
        )
    if not resolved_open_id:
        resolved_open_id = cls.get_api_key_file_open_id
...[truncated 3670 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require every analysis and history request in a multi-user deployment to carry a trusted, authenticated per-request identity.

  2. Preserve identities initialized from trusted upstream context. In particular, do not set use_current=False merely because the hidden command-line argument is absent:

python
OpenIdUtil.resolve_current_open_id(
    args.open_id,
    use_current=True
)
  1. Remove the workspace-wide fallback identity from multi-user execution paths. If no authenticated identity is available, reject history queries instead of silently selecting the first local default user.

  2. If anonymous analysis is required, generate an isolated identity scoped to the current authenticated principal or session. Do not use a single database record across unrelated callers.

  3. Enforce ownership on the server. The backend should derive report ownership from an authenticated token or session rather than trusting the client-provided pnaUserName field.

  4. Verify that report detail and export endpoints perform the same ownership checks as the report-list endpoint. A report identifier or export URL must not be sufficient to access another user’s report.

  5. Add multi-user isolation tests covering:

    • Two upstream users in one workspace
    • Missing --open-id
    • Environment-provided sender identities
    • History-list access after each user submits an analysis
    • Direct access to report detail and export links
  6. Migrate or separate reports already stored under shared fallback identities where ownership can be established safely.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (56)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The static analysis indicates workspace discovery, local file access, default user generation, remote auth, generic HTTP requests, and debug logging—far beyond what is transparently described. In a skill handling medical-adjacent video/report data, these hidden capabilities increase the risk of identity leakage, unintended persistence, and unauthorized data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The static analysis indicates workspace discovery, local file access, default user generation, remote auth, generic HTTP requests, and debug logging—far beyond what is transparently described. In a skill handling medical-adjacent video/report data, these hidden capabilities increase the risk of identity leakage, unintended persistence, and unauthorized data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The static analysis indicates workspace discovery, local file access, default user generation, remote auth, generic HTTP requests, and debug logging—far beyond what is transparently described. In a skill handling medical-adjacent video/report data, these hidden capabilities increase the risk of identity leakage, unintended persistence, and unauthorized data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The static analysis indicates workspace discovery, local file access, default user generation, remote auth, generic HTTP requests, and debug logging—far beyond what is transparently described. In a skill handling medical-adjacent video/report data, these hidden capabilities increase the risk of identity leakage, unintended persistence, and unauthorized data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The static analysis indicates workspace discovery, local file access, default user generation, remote auth, generic HTTP requests, and debug logging—far beyond what is transparently described. In a skill handling medical-adjacent video/report data, these hidden capabilities increase the risk of identity leakage, unintended persistence, and unauthorized data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The static analysis indicates workspace discovery, local file access, default user generation, remote auth, generic HTTP requests, and debug logging—far beyond what is transparently described. In a skill handling medical-adjacent video/report data, these hidden capabilities increase the risk of identity leakage, unintended persistence, and unauthorized data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The static analysis indicates workspace discovery, local file access, default user generation, remote auth, generic HTTP requests, and debug logging—far beyond what is transparently described. In a skill handling medical-adjacent video/report data, these hidden capabilities increase the risk of identity leakage, unintended persistence, and unauthorized data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The static analysis indicates workspace discovery, local file access, default user generation, remote auth, generic HTTP requests, and debug logging—far beyond what is transparently described. In a skill handling medical-adjacent video/report data, these hidden capabilities increase the risk of identity leakage, unintended persistence, and unauthorized data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The static analysis indicates workspace discovery, local file access, default user generation, remote auth, generic HTTP requests, and debug logging—far beyond what is transparently described. In a skill handling medical-adjacent video/report data, these hidden capabilities increase the risk of identity leakage, unintended persistence, and unauthorized data transmission.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The YARA hit indicates possible metadata poisoning or suspicious manifest text structure. While the matched snippet alone is not conclusive, in combination with the strong description/behavior mismatches and contradictory content, it suggests the manifest may be crafted or malformed in ways that obscure true behavior or influence tool interpretation.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "sport-analysis"
description: "Conducts video safety risk analysis for participants in outdoor sports competitions, long-distance running, marathons, etc.; identifies sports injuries and sudden health risks, outputs professional analysis reports, and provides timely warnings to ensure sports safety. | 户外体育赛事风险分析工具,针对户外体育比赛、长跑马拉松等运动项目的参赛人员进行视频安全风险分析,识别运动损伤和突发健康风险,输出专业分析报告,及时预警保障运动安全"
version: "1.0.18"
license: "MIT-0"
---

# 🏃 Outdoor Sports Event R

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation for a sports-risk analysis skill contains a contradictory paragraph describing smoking detection behavior. This kind of cross-domain inconsistency is a strong indicator of copy-paste or repurposed logic, and it raises serious concern that the skill may invoke unrelated detection workflows or mis-handle user media.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file exposes a generic API client surface for arbitrary HTTP operations and CRUD-style actions that are not constrained to the declared sports video safety-analysis purpose. In an agent skill context, this broad network capability can be repurposed to access, modify, or exfiltrate remote data through attacker-influenced URLs or parameters, expanding the skill far beyond least-privilege design.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The add, edit, and delete methods provide remote state-changing capabilities without any visible restriction tying them to a specific trusted service or the skill's stated safety-analysis workflow. In a skill that should primarily analyze sports footage and generate warnings, these mutation primitives materially increase the risk of unauthorized remote changes if other components can influence the target URL or payload.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file contains open-id generation, persistence, and local user-database integration that are unrelated to a sports video safety analysis skill. This creates hidden identity management behavior, including reuse of local identity artifacts and silent account association, which expands the skill's privileges and data handling beyond user expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The HTTP wrapper silently performs login/registration behavior via /sys/phoneLogin and caches tokens before making normal requests. For a sports-risk analysis tool, hidden remote account creation and token handling are out-of-scope and can cause unauthorized identity creation, unexpected network side effects, and privacy issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The request helper automatically attaches authentication headers and user-identifying fields such as pnaUserName, tenantCode, and platform metadata to outbound requests. Combined with silent token retrieval and account creation, this creates undisclosed external transmission of identity and auth material beyond the skill's advertised purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill declares broad operational behavior involving shell execution, filesystem access, network access, and environment usage, but does not define any explicit tool/permission scope. That makes the runtime trust boundary unclear and increases the chance of unintended command execution, data access, or exfiltration if the skill is triggered in a permissive agent environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The default trigger is broad enough to activate on generic sports video requests, which can cause unintended handling of user files or URLs. Overbroad activation is especially risky here because the skill has network, file, and shell-related behavior and may process sensitive media without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The automatic history-report query trigger uses vague phrases that may match ordinary reporting requests and cause cloud lookups unexpectedly. That can expose or retrieve prior user-linked records without sufficiently specific intent, creating privacy and authorization concerns.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill accepts videos, images, files, and URLs and sends analysis/report queries to remote services, but the description lacks a clear privacy and data-handling warning. Because the content may include health-adjacent and identity-linked data, omission of this disclosure materially increases privacy risk and undermines informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The returned user-facing string is fixed in Chinese ("户外体育赛事风险分析结构化结果"). Forcing a specific language in output without offering user choice or documenting a justified locale restriction is a natural-language policy violation under the language/locale rule.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The tool forwards local video paths or remote video URLs to an external analysis mechanism without an explicit privacy warning or informed consent flow. In this skill context, the videos may contain identifiable participants and health-related risk information, so undisclosed transmission can expose sensitive personal data and create compliance/privacy issues.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI contains hidden identity resolution and history-listing behavior beyond the advertised purpose of single video safety analysis. Because it can derive or use an OpenID and list prior analyses, it introduces unauthorized metadata exposure and function creep, especially if callers are unaware that account-scoped history may be accessed.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2