Back to skill

Security audit

Workplace Group Stress Heatmap | 职场员工压力群体热力图

Security checks for vulnerabilities and agentic risk

Overview

This skill needs careful review because it sends sensitive workplace camera media to a cloud API while silently creating and persisting account-linked identities despite anonymity claims.

Before installing, confirm that your organization has employee notice and consent, understands that videos or URLs are sent to a third-party cloud service, and accepts local/remote account-linked report history. Do not treat the skill as fully anonymous unless the provider documents retention, access controls, deletion, and proof that employee-level identifiers or small-group re-identification are not possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (51)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymous group stress analysis from office-camera footage, but the documented/observed behavior appears to be generic backend API access, report listing, identity handling, and unrelated parameters rather than the described analytics. This mismatch is dangerous because it can mislead reviewers and users about what data is collected, where it is sent, and what operations the skill actually performs, creating a strong risk of covert data handling and deceptive consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest claims anonymous group stress analysis from office-camera footage, but the documented/observed behavior appears to be generic backend API access, report listing, identity handling, and unrelated parameters rather than the described analytics. This mismatch is dangerous because it can mislead reviewers and users about what data is collected, where it is sent, and what operations the skill actually performs, creating a strong risk of covert data handling and deceptive consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The manifest claims anonymous group stress analysis from office-camera footage, but the documented/observed behavior appears to be generic backend API access, report listing, identity handling, and unrelated parameters rather than the described analytics. This mismatch is dangerous because it can mislead reviewers and users about what data is collected, where it is sent, and what operations the skill actually performs, creating a strong risk of covert data handling and deceptive consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest claims anonymous group stress analysis from office-camera footage, but the documented/observed behavior appears to be generic backend API access, report listing, identity handling, and unrelated parameters rather than the described analytics. This mismatch is dangerous because it can mislead reviewers and users about what data is collected, where it is sent, and what operations the skill actually performs, creating a strong risk of covert data handling and deceptive consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The manifest claims anonymous group stress analysis from office-camera footage, but the documented/observed behavior appears to be generic backend API access, report listing, identity handling, and unrelated parameters rather than the described analytics. This mismatch is dangerous because it can mislead reviewers and users about what data is collected, where it is sent, and what operations the skill actually performs, creating a strong risk of covert data handling and deceptive consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The manifest claims anonymous group stress analysis from office-camera footage, but the documented/observed behavior appears to be generic backend API access, report listing, identity handling, and unrelated parameters rather than the described analytics. This mismatch is dangerous because it can mislead reviewers and users about what data is collected, where it is sent, and what operations the skill actually performs, creating a strong risk of covert data handling and deceptive consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest claims anonymous group stress analysis from office-camera footage, but the documented/observed behavior appears to be generic backend API access, report listing, identity handling, and unrelated parameters rather than the described analytics. This mismatch is dangerous because it can mislead reviewers and users about what data is collected, where it is sent, and what operations the skill actually performs, creating a strong risk of covert data handling and deceptive consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymous group stress analysis from office-camera footage, but the documented/observed behavior appears to be generic backend API access, report listing, identity handling, and unrelated parameters rather than the described analytics. This mismatch is dangerous because it can mislead reviewers and users about what data is collected, where it is sent, and what operations the skill actually performs, creating a strong risk of covert data handling and deceptive consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymous group stress analysis from office-camera footage, but the documented/observed behavior appears to be generic backend API access, report listing, identity handling, and unrelated parameters rather than the described analytics. This mismatch is dangerous because it can mislead reviewers and users about what data is collected, where it is sent, and what operations the skill actually performs, creating a strong risk of covert data handling and deceptive consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymous group stress analysis from office-camera footage, but the documented/observed behavior appears to be generic backend API access, report listing, identity handling, and unrelated parameters rather than the described analytics. This mismatch is dangerous because it can mislead reviewers and users about what data is collected, where it is sent, and what operations the skill actually performs, creating a strong risk of covert data handling and deceptive consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The manifest claims anonymous group stress analysis from office-camera footage, but the documented/observed behavior appears to be generic backend API access, report listing, identity handling, and unrelated parameters rather than the described analytics. This mismatch is dangerous because it can mislead reviewers and users about what data is collected, where it is sent, and what operations the skill actually performs, creating a strong risk of covert data handling and deceptive consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymous group stress analysis from office-camera footage, but the documented/observed behavior appears to be generic backend API access, report listing, identity handling, and unrelated parameters rather than the described analytics. This mismatch is dangerous because it can mislead reviewers and users about what data is collected, where it is sent, and what operations the skill actually performs, creating a strong risk of covert data handling and deceptive consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymous group stress analysis from office-camera footage, but the documented/observed behavior appears to be generic backend API access, report listing, identity handling, and unrelated parameters rather than the described analytics. This mismatch is dangerous because it can mislead reviewers and users about what data is collected, where it is sent, and what operations the skill actually performs, creating a strong risk of covert data handling and deceptive consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims anonymous group stress analysis from office-camera footage, but the documented/observed behavior appears to be generic backend API access, report listing, identity handling, and unrelated parameters rather than the described analytics. This mismatch is dangerous because it can mislead reviewers and users about what data is collected, where it is sent, and what operations the skill actually performs, creating a strong risk of covert data handling and deceptive consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation introduces hidden internal identity association and automatic default-user creation despite claiming anonymous group analysis. This is especially dangerous in a workplace surveillance context because it creates an account-linked audit trail that could enable tracking, correlation of reports over time, and hidden data subject linkage contrary to the stated anonymity guarantees.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script exposes retrieval of analysis history tied to an open_id, which conflicts with the stated anonymous, group-level heatmap purpose. In this context, linking and enumerating user-associated history can enable tracking, re-identification, or unauthorized access to prior analyses, making the privacy risk materially higher than in a generic media-processing tool.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest claims anonymous group-level analysis, yet the code persists identifiable user records and authentication-like tokens (username, realname, email, token, open_token). In the context of employee stress surveillance, this contradiction is especially dangerous because it enables linkage of sensitive inferred mental-state data to specific individuals and creates privacy, compliance, and insider-abuse risks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code reads local identity material from the workspace and, if absent, creates fallback user identities persisted in local storage. For a skill advertised as anonymous group analytics, this is a significant capability mismatch that can silently bind activity to a durable identity and undermine user expectations around anonymity and scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This utility layer performs remote account provisioning, token acquisition, and authenticated API calls that materially exceed the skill's stated anonymous stress-heatmap purpose. In this context, hidden identity bootstrapping and outbound tokenized access create an undeclared data/identity channel and expand the blast radius if the skill is installed or reused in a sensitive workplace environment.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises and documents capabilities that involve shell execution, filesystem access, environment access, and network access, but it does not declare any explicit tool scope or permissions boundary. In a skill that also auto-saves attachments and invokes external scripts/APIs, this lack of least-privilege declaration increases the chance of unintended file access, command execution, or data egress beyond the user's expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes continuous workplace stress surveillance using fixed cameras, but the main overview does not prominently foreground privacy, employment, and misuse risks. In an employment setting, emotion/posture inference can affect worker autonomy, trust, and potentially employment decisions, so under-warning materially increases the chance of harmful deployment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill claims to perform only anonymous, group-level analysis, yet it also supports cloud-based historical report querying and report-link retrieval. That expands the data lifecycle and sharing surface beyond a one-time anonymous heatmap, increasing the risk that aggregated outputs become trackable, retained, or repurposed without clear user understanding.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation says the skill is anonymous and does not identify individuals, but later workflow sections describe internal identity initialization and user creation. Contradictory privacy claims are dangerous because they undermine informed consent and may hide data association practices that users and administrators would reasonably consider material.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default trigger activates on uploaded office-camera video even without a specific request for stress analysis. That can lead to sensitive workplace footage being automatically processed and sent through analysis pipelines without sufficiently explicit user intent, which is especially risky given the surveillance and privacy sensitivity of the content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The history-report query auto-trigger relies on broad keywords and lacks exclusion criteria or confirmation, so users may unintentionally invoke cloud-side retrieval of prior reports. In a workplace-monitoring context, unintended retrieval of historical surveillance-derived records increases privacy exposure and can reveal sensitive organizational patterns.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2