Back to skill

Security audit

Vocalization Health Analysis | 畜禽声纹健康分析

Security checks for vulnerabilities and agentic risk

Overview

This skill is a cloud media-analysis wrapper, but it silently creates and reuses identities, stores auth tokens, and defaults to plaintext development endpoints, so it needs review before installation.

Install only if you are comfortable with this skill sending media and identity-linked report requests to the publisher's cloud service. Before use, verify the service configuration is production HTTPS, correct the YAML dependency, and understand that the skill may create a local default identity and cache bearer-style tokens in a shared workspace database.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/config.yaml:1
Finding

Default Development Configuration Transmits Sensitive Data over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smyx_common/scripts/dao.py:448
Finding

Authentication Tokens Are Persisted Unencrypted in a Shared SQLite Database

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smyx_common/scripts/config.py:148
Finding

Platform-Dependent HTTP Debugging Can Leak Authentication Headers and Request Bodies

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skills/smyx_analysis/requirements.txt:1
Finding

Incorrect YAML Distribution Name Creates Dependency Confusion Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (58)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to handle auth tokens, authorization headers, user/open-id resolution, API-key files, and workspace data access while not actually implementing the promised acoustic analysis locally. This combination is dangerous because it couples sensitive credentials and identity workflows with a misleadingly benign description, increasing the chance of overpermissioned deployment.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-vocalization-health-analysis-analysis"
description: "Analyzes acoustic features (frequency, duration, pitch, intensity) of livestock and poultry vocalizations to detect abnormal sounds such as coughing, wheezing, painful screams and hoarse calls, and outputs respiratory health risk hints. | 通过叫声分析识别畜禽呼吸道疾病等健康问题。"
version: "1.0.8"
license: "MIT-0"
---

# 🔊 Livestock Vocalization Health Analysis | 畜禽声纹健康分析

> 通过叫声分析识别畜禽呼吸道疾病等健康问题。
>
> **非接触式群体健康筛查中枢** · 畜禽舍音频智能分析 · 咳嗽/喘息/尖叫/嘶

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file’s implementation and CLI behavior are for video analysis and video-history listing, while the skill metadata claims livestock/poultry vocalization health analysis. This mismatch is dangerous because users, orchestrators, or policy gates may grant the skill access and trust based on its declared purpose, but the code performs materially different operations, enabling capability smuggling and inappropriate handling of user data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The add, edit, delete, http_post, and http_put methods expose arbitrary remote modification capability through caller-supplied URLs and arguments, which is far broader than needed for a vocalization analysis skill. If reachable by prompts, tool chaining, or untrusted inputs, this could be abused to alter remote resources, trigger unauthorized state changes, or pivot the skill into a generic remote action tool.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file defines a generic user/account persistence layer, including lookup and update methods for usernames and real names, which is unrelated to livestock vocalization health analysis. In this skill context, hidden account-management capability materially increases the risk of covert data collection or repurposing the skill beyond its declared function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The User model stores personal profile data and authentication-like secrets such as token and open_token, none of which are justified by an audio-based livestock health analysis feature. In a mismatched skill, collecting and persisting such data creates unnecessary exposure of credentials and personal information if the local database is accessed or exfiltrated.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code inspects the agent runtime environment, discovers workspace roots, and creates data/skills directories, capabilities that exceed what is needed for acoustic health analysis. In this context, environment-aware workspace discovery increases the ability of the skill to map host layout, persist data, and potentially affect other agent resources beyond its declared function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This code reads identity values from workspace files, queries a local user database, and generates persistent default identities when none exist. For a vocalization-analysis skill, silent identity resolution and persistence are unjustified and dangerous because they can impersonate or create user context without informed consent and become the basis for later authenticated network actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility performs account provisioning, token retrieval, local token persistence, and authenticated remote login flows that are unrelated to livestock vocalization health analysis. In the context of a narrowly scoped analysis skill, hidden identity bootstrapping and outbound authentication materially expand the trust boundary and can transmit or create user identities without clear consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares no explicit tool scope despite instructing use of shell execution, network access, file reads/writes, and environment-backed identity/config handling. This increases the blast radius of the skill and makes privilege boundaries unclear, which is dangerous for an agent platform because the agent may invoke more capabilities than users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Overly broad natural-language trigger keywords for history queries can cause unintended automatic invocation of cloud record retrieval when a user casually mentions reports. Because historical reports are identity-linked and remotely fetched, accidental triggering can expose more data than the user intended to access in that interaction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill says uploaded files are automatically saved locally, but it does not clearly present retention, storage location, or deletion behavior to the user. Silent persistence of uploaded audio/video is risky because those files may contain sensitive operational or incidental human speech data and could remain accessible beyond the immediate task.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says the skill analyzes livestock and poultry vocalizations for respiratory health hints, but the CLI restricts --pet-type to cat, dog, or other, and the function parameter is also named pet_type. This indicates the implementation is reused from a pet-animal analyzer rather than a livestock/poultry-specific tool, creating a semantic mismatch between the advertised scope and actual behavior.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2