T09 · Insecure Skill Coding Practices
- Location
skills/smyx_common/scripts/config.yaml:1- Finding
Default Development Configuration Transmits Sensitive Data over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a cloud media-analysis wrapper, but it silently creates and reuses identities, stores auth tokens, and defaults to plaintext development endpoints, so it needs review before installation.
Install only if you are comfortable with this skill sending media and identity-linked report requests to the publisher's cloud service. Before use, verify the service configuration is production HTTPS, correct the YAML dependency, and understand that the skill may create a local default identity and cache bearer-style tokens in a shared workspace database.
skills/smyx_common/scripts/config.yaml:1Default Development Configuration Transmits Sensitive Data over Plaintext HTTP
skills/smyx_common/scripts/dao.py:448Authentication Tokens Are Persisted Unencrypted in a Shared SQLite Database
skills/smyx_common/scripts/config.py:148Platform-Dependent HTTP Debugging Can Leak Authentication Headers and Request Bodies
skills/smyx_analysis/requirements.txt:1Incorrect YAML Distribution Name Creates Dependency Confusion Risk
The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.
The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.
The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.
The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.
The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.
The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.
The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.
The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.
The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.
The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.
The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.
The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
---
name: "smyx-vocalization-health-analysis-analysis"
description: "Analyzes acoustic features (frequency, duration, pitch, intensity) of livestock and poultry vocalizations to detect abnormal sounds such as coughing, wheezing, painful screams and hoarse calls, and outputs respiratory health risk hints. | 通过叫声分析识别畜禽呼吸道疾病等健康问题。"
version: "1.0.8"
license: "MIT-0"
---
# 🔊 Livestock Vocalization Health Analysis | 畜禽声纹健康分析
> 通过叫声分析识别畜禽呼吸道疾病等健康问题。
>
> **非接触式群体健康筛查中枢** · 畜禽舍音频智能分析 · 咳嗽/喘息/尖叫/嘶
The file’s implementation and CLI behavior are for video analysis and video-history listing, while the skill metadata claims livestock/poultry vocalization health analysis. This mismatch is dangerous because users, orchestrators, or policy gates may grant the skill access and trust based on its declared purpose, but the code performs materially different operations, enabling capability smuggling and inappropriate handling of user data.
The add, edit, delete, http_post, and http_put methods expose arbitrary remote modification capability through caller-supplied URLs and arguments, which is far broader than needed for a vocalization analysis skill. If reachable by prompts, tool chaining, or untrusted inputs, this could be abused to alter remote resources, trigger unauthorized state changes, or pivot the skill into a generic remote action tool.
The file defines a generic user/account persistence layer, including lookup and update methods for usernames and real names, which is unrelated to livestock vocalization health analysis. In this skill context, hidden account-management capability materially increases the risk of covert data collection or repurposing the skill beyond its declared function.
The User model stores personal profile data and authentication-like secrets such as token and open_token, none of which are justified by an audio-based livestock health analysis feature. In a mismatched skill, collecting and persisting such data creates unnecessary exposure of credentials and personal information if the local database is accessed or exfiltrated.
The code inspects the agent runtime environment, discovers workspace roots, and creates data/skills directories, capabilities that exceed what is needed for acoustic health analysis. In this context, environment-aware workspace discovery increases the ability of the skill to map host layout, persist data, and potentially affect other agent resources beyond its declared function.
This code reads identity values from workspace files, queries a local user database, and generates persistent default identities when none exist. For a vocalization-analysis skill, silent identity resolution and persistence are unjustified and dangerous because they can impersonate or create user context without informed consent and become the basis for later authenticated network actions.
This utility performs account provisioning, token retrieval, local token persistence, and authenticated remote login flows that are unrelated to livestock vocalization health analysis. In the context of a narrowly scoped analysis skill, hidden identity bootstrapping and outbound authentication materially expand the trust boundary and can transmit or create user identities without clear consent.
The skill declares no explicit tool scope despite instructing use of shell execution, network access, file reads/writes, and environment-backed identity/config handling. This increases the blast radius of the skill and makes privilege boundaries unclear, which is dangerous for an agent platform because the agent may invoke more capabilities than users expect.
Overly broad natural-language trigger keywords for history queries can cause unintended automatic invocation of cloud record retrieval when a user casually mentions reports. Because historical reports are identity-linked and remotely fetched, accidental triggering can expose more data than the user intended to access in that interaction.
The skill says uploaded files are automatically saved locally, but it does not clearly present retention, storage location, or deletion behavior to the user. Silent persistence of uploaded audio/video is risky because those files may contain sensitive operational or incidental human speech data and could remain accessible beyond the immediate task.
The manifest says the skill analyzes livestock and poultry vocalizations for respiratory health hints, but the CLI restricts --pet-type to cat, dog, or other, and the function parameter is also named pet_type. This indicates the implementation is reused from a pet-animal analyzer rather than a livestock/poultry-specific tool, creating a semantic mismatch between the advertised scope and actual behavior.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)
result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
dict) else result_json
if result_json_common_ai_response:
result_json = result_json_common_ai_response
Detected: suspicious.install_untrusted_source