Back to skill

Security audit

Intelligent Video Search & Retrieval Analysis Skill | 视频搜索检索智能分析技能

Security checks for vulnerabilities and agentic risk

Overview

This is a cloud-backed video analysis skill that is mostly purpose-related, but it silently creates or reuses a service identity, stores tokens locally, and sends media and identity data to remote services.

Review before installing. Use this only if you are comfortable with a remote service receiving your videos or video URLs, creating or reusing an account identity, storing local service tokens, and maintaining cloud report history. Avoid sensitive, regulated, or private surveillance media unless the service's retention and deletion practices are acceptable to you.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
skills/smyx_common/scripts/util.py:568
Finding

Authentication Credentials Can Be Forwarded to Untrusted Network Origins

Content
View full analysis
Remediation
View remediation

other

Warning
Location
skills/smyx_common/scripts/util.py:544
Finding

Platform Sender Identity Is Silently Disclosed and Reused as a Mobile Login Identifier

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (54)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation itself discloses implicit user identity handling, local persistence, and external API use, all under a narrow video-search label. Hidden or underemphasized identity generation/persistence is particularly dangerous because it can create silent account linkage, cross-session tracking, and unauthorized access to historical reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documentation itself discloses implicit user identity handling, local persistence, and external API use, all under a narrow video-search label. Hidden or underemphasized identity generation/persistence is particularly dangerous because it can create silent account linkage, cross-session tracking, and unauthorized access to historical reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The documentation itself discloses implicit user identity handling, local persistence, and external API use, all under a narrow video-search label. Hidden or underemphasized identity generation/persistence is particularly dangerous because it can create silent account linkage, cross-session tracking, and unauthorized access to historical reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documentation itself discloses implicit user identity handling, local persistence, and external API use, all under a narrow video-search label. Hidden or underemphasized identity generation/persistence is particularly dangerous because it can create silent account linkage, cross-session tracking, and unauthorized access to historical reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documentation itself discloses implicit user identity handling, local persistence, and external API use, all under a narrow video-search label. Hidden or underemphasized identity generation/persistence is particularly dangerous because it can create silent account linkage, cross-session tracking, and unauthorized access to historical reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documentation itself discloses implicit user identity handling, local persistence, and external API use, all under a narrow video-search label. Hidden or underemphasized identity generation/persistence is particularly dangerous because it can create silent account linkage, cross-session tracking, and unauthorized access to historical reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation itself discloses implicit user identity handling, local persistence, and external API use, all under a narrow video-search label. Hidden or underemphasized identity generation/persistence is particularly dangerous because it can create silent account linkage, cross-session tracking, and unauthorized access to historical reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation itself discloses implicit user identity handling, local persistence, and external API use, all under a narrow video-search label. Hidden or underemphasized identity generation/persistence is particularly dangerous because it can create silent account linkage, cross-session tracking, and unauthorized access to historical reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation itself discloses implicit user identity handling, local persistence, and external API use, all under a narrow video-search label. Hidden or underemphasized identity generation/persistence is particularly dangerous because it can create silent account linkage, cross-session tracking, and unauthorized access to historical reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation itself discloses implicit user identity handling, local persistence, and external API use, all under a narrow video-search label. Hidden or underemphasized identity generation/persistence is particularly dangerous because it can create silent account linkage, cross-session tracking, and unauthorized access to historical reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation itself discloses implicit user identity handling, local persistence, and external API use, all under a narrow video-search label. Hidden or underemphasized identity generation/persistence is particularly dangerous because it can create silent account linkage, cross-session tracking, and unauthorized access to historical reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation itself discloses implicit user identity handling, local persistence, and external API use, all under a narrow video-search label. Hidden or underemphasized identity generation/persistence is particularly dangerous because it can create silent account linkage, cross-session tracking, and unauthorized access to historical reports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation itself discloses implicit user identity handling, local persistence, and external API use, all under a narrow video-search label. Hidden or underemphasized identity generation/persistence is particularly dangerous because it can create silent account linkage, cross-session tracking, and unauthorized access to historical reports.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-video-search-analysis"
description: "Conducts intelligent video search based on target and semantic descriptions; supports conventional target retrieval, natural language description retrieval, and vectorized model matching. | 视频搜索/视频检索智能分析技能,基于目标、语义描述进行智能视频搜索,支持常规目标检索、自然语言描述检索、向量化模型匹配"
version: "1.0.5"
license: "MIT-0"
---

# 🔎 Intelligent Video Search & Retrieval Analysis Skill | 视频搜索检索智能分析技能
> **智能分析中枢** · 图片/视频智能分析 · 结构化报告 · 历史

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill for intelligent video search and retrieval based on targets, semantic descriptions, and vector matching. This file instead uploads or references a video for analysis, polls for report completion, lists prior analysis reports, and generates export-image URLs for reports; there is no implementation of search queries, target retrieval, semantic description matching, or vectorized model matching in the shown code.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The HTTP helper can silently register/login a user against an external endpoint via /sys/phoneLogin when tokens are absent, using inferred local identity values. This is dangerous because a broadly reusable utility function for all requests embeds undisclosed account creation/authentication behavior and external data transmission unrelated to the stated video-search purpose, potentially causing unintended account linkage and exfiltration of local identifiers.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares powerful capabilities in its documentation and workflow (shell execution, network access, local file handling, environment/config use) but does not define any explicit tool scope or permissions boundary. In an agent environment, this creates unnecessary ambiguity about what the skill may access and increases the chance of over-privileged execution or unsafe tool invocation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a retrieval skill, but the body documents persistent report handling and cloud report listing beyond simple analysis. This divergence can mislead security reviewers and orchestrators about the skill's actual data lifecycle and retention characteristics.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The default trigger is broad enough that ordinary requests about searching video content may automatically invoke the skill. Overly broad activation increases the chance of unintended file saving, network transfer, or report lookup without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill introduces cloud-based history lookup and automatic local user creation/reuse even though its stated purpose is video search. These side behaviors expand data collection and retention, and they can expose prior reports or create persistent identities without clear user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow says uploaded attachments are automatically saved locally and remote URLs are sent to an API service, but the skill description does not prominently warn users about these data-handling behaviors. This creates a meaningful privacy and data-exfiltration risk because sensitive local media or remote resources may be persisted or transmitted unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code presents the tool description, argument help text, and user-facing status messages only in Chinese. For a general-purpose skill, forcing a specific language without offering a user choice or documenting a locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 28)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · skills/smyx_analysis/scripts/skill.py (reported line 33)May include surrounding context.

python
result_json = JsonUtil.parse(result_json_pure_text, result_json_pure_text)

        result_json_common_ai_response = result_json.get("commonAiResponse") if isinstance(result_json,
                                                                                           dict) else result_json
        if result_json_common_ai_response:
            result_json = result_json_common_ai_response

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill reads arbitrary local file contents and sends them to a remote analysis service, but this code provides no explicit user-facing consent flow, warning, or restriction beyond file extension and size checks. In an agent setting, that increases the risk of inadvertent sensitive-data exfiltration if a user or upstream component passes a confidential local video or mislabeled file.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2