Back to skill

Security audit

Child Learning Behavior Analysis Tool | 孩子学习行为分析工具

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real cloud-based student video analysis skill, but it should be reviewed because it silently links users to remote accounts and stores access tokens while handling child video data.

Review this before installing in any environment with real student or child footage. Use it only if you are comfortable sending videos or URLs to the configured cloud service, having reports tied to an internal user identity, and allowing local token/session data to be kept in the workspace data directory. Prefer explicit consent and a dedicated test workspace/account until the publisher documents retention, deletion, and token-handling controls more clearly.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (59)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch combines undeclared filesystem access, local credential/API-key handling, local user-record persistence, outbound authentication/network requests, and token processing under the cover of an educational child-analysis skill. Because the subject matter involves minors and family behavior data, misleading packaging around identity, credentials, and remote data flows substantially increases privacy, consent, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch combines undeclared filesystem access, local credential/API-key handling, local user-record persistence, outbound authentication/network requests, and token processing under the cover of an educational child-analysis skill. Because the subject matter involves minors and family behavior data, misleading packaging around identity, credentials, and remote data flows substantially increases privacy, consent, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch combines undeclared filesystem access, local credential/API-key handling, local user-record persistence, outbound authentication/network requests, and token processing under the cover of an educational child-analysis skill. Because the subject matter involves minors and family behavior data, misleading packaging around identity, credentials, and remote data flows substantially increases privacy, consent, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch combines undeclared filesystem access, local credential/API-key handling, local user-record persistence, outbound authentication/network requests, and token processing under the cover of an educational child-analysis skill. Because the subject matter involves minors and family behavior data, misleading packaging around identity, credentials, and remote data flows substantially increases privacy, consent, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch combines undeclared filesystem access, local credential/API-key handling, local user-record persistence, outbound authentication/network requests, and token processing under the cover of an educational child-analysis skill. Because the subject matter involves minors and family behavior data, misleading packaging around identity, credentials, and remote data flows substantially increases privacy, consent, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch combines undeclared filesystem access, local credential/API-key handling, local user-record persistence, outbound authentication/network requests, and token processing under the cover of an educational child-analysis skill. Because the subject matter involves minors and family behavior data, misleading packaging around identity, credentials, and remote data flows substantially increases privacy, consent, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch combines undeclared filesystem access, local credential/API-key handling, local user-record persistence, outbound authentication/network requests, and token processing under the cover of an educational child-analysis skill. Because the subject matter involves minors and family behavior data, misleading packaging around identity, credentials, and remote data flows substantially increases privacy, consent, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch combines undeclared filesystem access, local credential/API-key handling, local user-record persistence, outbound authentication/network requests, and token processing under the cover of an educational child-analysis skill. Because the subject matter involves minors and family behavior data, misleading packaging around identity, credentials, and remote data flows substantially increases privacy, consent, and unauthorized-access risk.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

The metadata was flagged for tool/manifest poisoning indicators, and the manifest uses unusually long, repetitive, multilingual descriptive content that can be used to manipulate routing, trust, or tool-selection heuristics. While not conclusive on its own, in combination with the other description-behavior mismatches it increases suspicion that the metadata is engineered to oversell legitimacy while obscuring actual behavior.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "study-analysis"
description: "Conducts video analysis of learning behavior for children/students, identifies poor learning habits, provides structured analysis reports and family education improvement suggestions, focusing on learning habit cultivation and behavior correction. | A comprehensive tool designed to analyze video footage of children's and students' learning behaviors. It identifies poor study habits and provides structured analysis reports along with actionable suggestions for family education improvements. The tool is dedicated to fostering positive study habits and facilitating behavioral correc

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file exposes broad generic CRUD and arbitrary HTTP client wrappers that are not constrained to the declared study-behavior video analysis purpose. In a skill handling sensitive child/student learning data, these capabilities can be repurposed to send data to unintended endpoints, perform unauthorized backend actions, or expand the skill into a general network proxy beyond its stated scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The http_post/http_put/http_get/http_delete methods accept arbitrary URLs and forward requests directly, creating a general outbound network primitive inside a child-study analysis skill. That greatly increases abuse potential for data exfiltration, access to unexpected internal or external services, and bypass of intended product boundaries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The model stores token and open_token fields despite no clear justification in the declared study-analysis purpose. Persisting authentication-style secrets in a child/student-oriented application significantly raises the impact of compromise because token theft can enable account takeover or unauthorized API access beyond this skill itself.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This utility code performs workspace discovery, creates directories, reads and writes persistent local state, and manages agent-scoped identity data far beyond the advertised purpose of analyzing student study videos. That mismatch is dangerous because it expands the skill's access to the host environment and establishes persistence primitives that could be abused for cross-skill data access, tracking, or later unauthorized operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code can silently create or log in users against external services, cache tokens, and reuse them for subsequent API calls. For a study-behavior video analysis skill, this is unjustified credentialed network behavior and creates a clear risk of undisclosed account creation, identity binding, token persistence, and unauthorized remote actions under a local or inferred user identity.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool-scope restrictions even though the manifest instructs use of shell execution, local file handling, network access, and environment-backed identity/config behavior. This creates an over-privileged and under-specified execution surface where an agent may invoke sensitive capabilities without clear policy boundaries or least-privilege controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The default trigger condition is broad enough that ordinary discussion of study habits or uploaded media may activate the skill without sufficiently specific user intent. Over-broad auto-triggering is dangerous because it can cause unexpected processing of sensitive child videos or files and unintended transmission to remote services.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Automatic history-report retrieval on broad phrases like viewing reports can expose sensitive historical analysis data without strong confirmation or context checks. In a family/child setting, inadvertent retrieval of prior reports can reveal behavioral assessments and linked report URLs to the wrong conversation or user context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file contains user-facing instructions and output examples that prescribe Chinese-language report presentation and examples, while the skill itself is bilingual and does not state that the user may choose their preferred language. That creates a locale/language constraint without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation states that the API supports file uploads and uses API-key authentication, but it omits any warning or guidance about handling sensitive student video data, retention, sharing, or consent requirements. In the context of children's learning-behavior analysis, this omission is more dangerous because users may upload highly sensitive recordings of minors without understanding privacy, legal, or data-protection implications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

User-facing strings throughout the script, including errors, help text, progress messages, and results, are presented only in Chinese. The file does not offer a language or locale selection mechanism, so it imposes a specific language on users without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The analysis path forwards a local file path or URL to skill.get_output_analysis, and the code catches requests exceptions, indicating remote processing without an explicit warning to the user. Sending children's study videos or URLs to a remote service without clear disclosure creates a substantial privacy risk, especially because such media may contain minors and household context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function show_analyze_list retrieves analysis history/list data, which is not part of the described functionality of uploading or analyzing a video. Undisclosed access to historical records can reveal sensitive behavioral-analysis outputs and metadata about children or students, making this a meaningful privacy issue.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI includes hidden identity handling and a non-obvious history/listing capability that goes beyond the manifest's stated purpose of analyzing a provided video and returning a report. Hidden identity resolution combined with history retrieval can expose prior analyses tied to a user account without clear disclosure or consent, creating a privacy and scope-creep risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code invokes internal identity resolution while suppressing the related argument from normal help output, reducing user visibility into account linkage. In a skill handling child/student behavioral analysis, undisclosed identity association increases privacy sensitivity because outputs may be tied to a specific person's history and profile.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2