Back to skill

Security audit

S2 零隐私老人守护者智能体

Security checks for vulnerabilities and agentic risk

Overview

This elderly fall-detection skill is purpose-aligned, but it handles sensitive health/activity data with weak disclosure, broad persistence, and an unvalidated alert endpoint.

Review before installing. This skill should only be used where the monitored person or authorized caregiver has explicitly agreed to health/activity logging and alert sharing. Configure S2_BUS_ENDPOINT only to a trusted, authenticated local service, and avoid deployment unless retention, deletion, encryption, and recipient controls are defined.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
core/s2_elderly_guardian_agent.py:76
Finding

Unrestricted Alert Endpoint Enables SSRF and Sensitive Health-Event Disclosure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

Lines L45-L46 define S2-Elderly-Guardian as a 'space physiological sentinel' that is 'absolutely forbidden' from executing physical operations, but the very next lines describe it emitting a CRITICAL_FALL_DETECTED event that leads to an L1 hub deciding whether to issue an unlock/fail-open command. While indirect, the documented behavior positions the sentinel as the initiating cause of a physical security action, which contradicts the absolute phrasing of the documentation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill markets itself as 'zero privacy invasion' while also directing local persistence of gait-degradation data for future medical research. Health-related behavioral telemetry about elderly users is sensitive data, and retaining it without clear minimization, consent, retention limits, or de-identification creates a real privacy and compliance risk; the misleading claim further increases the chance operators deploy it under false assumptions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Broadcasting critical fall alerts to a medical platform or smart-home bus is functionally appropriate for the skill, but the documentation provides no explicit warning, consent, authentication, or scoping around external transmission of sensitive health events. In practice, an alert that an elderly person has suffered a critical fall is sensitive medical/status data, and sending it over an IPC or external endpoint without documented safeguards can leak private information or be misrouted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs local storage of elderly gait-degradation data for future medical research without any user-facing notice, consent flow, retention policy, or privacy safeguards. Because this is health-adjacent data tied to a vulnerable population, silent retention can expose sensitive behavioral profiles and create significant privacy, legal, and misuse risks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code persistently writes ADL and fall-related logs containing subject identity, timestamps, and health/activity events to local disk without any visible retention policy, access control, encryption, or declared authorization boundary. In an elderly-care context, these records are sensitive health/behavioral data, so unnecessary local retention increases privacy exposure if the host is shared, compromised, or logs are later repurposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function writes sensitive activity and health-adjacent logs to disk without any consent, notice, or confirmation flow for the monitored subject or operator. In this context, even routine activity records can reveal behavioral patterns and medical events, making undisclosed collection and retention a meaningful privacy risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The agent transmits fall-alert data, including a persistent identifier and subject-related emergency message, to an environment-configured network endpoint without any explicit consent, destination validation, or user-facing warning. Because this is health/emergency data, silent exfiltration to a misconfigured or attacker-controlled endpoint could disclose sensitive information or operational metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple user-facing labels and status strings are presented only in Chinese, including the dashboard name, title, module titles, and alert text. Under the policy, forcing a specific language without offering a language or locale choice is a natural-language policy violation unless clearly justified as region-specific, which is not documented here.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.md (reported line 11)May include surrounding context.

md
Permission is hereby granted, free of charge, to any person obtaining a copy of this Software for **personal, academic, non-commercial research, and individual home care purposes**. You may modify, run, and evaluate the Software locally within your own private residential spaces.

### 2. Commercial Use & Integrators (Restricted Tier)
**Strictly Prohibited without Explicit Authorization:** Any use of this Software for commercial purposes—including but not limited to system integration (SI), deployment in commercial eldercare facilities, nursing homes, hospitals, real estate projects, or offering the Software as a SaaS/PaaS service—is strictly prohibited without a formal commercial license from Space2.world.

### 3. Identity and Addressing Standards (SUNS & S2-DID)
The algorithms governing the generation of SUNS physical addresses and 22-digit S2-DID identities are proprietary to the S2 ecosystem. You may not extract, reverse-engineer, or establish competing registry networks using these protocols.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing natural-language content exclusively in Chinese, and nowhere indicates that the skill is region-specific or that users may choose another language. Under the language/locale policy rule, forcing a single language without opt-in can be a policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The comment suggests that creating an on-disk directory somehow makes storage access legitimate, but the code simply performs local persistence regardless of whether such data collection was authorized. This is dangerous because it normalizes bypassing governance/permission expectations and can mislead reviewers into accepting unauthorized storage of sensitive data.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This is a JSON manifest file, so vague-trigger checks apply. The name describes the skill broadly as an elderly health spatiotemporal dashboard but provides no explicit activation phrases, context limits, or exclusion conditions, making it unclear when this skill should be invoked versus other health or dashboard-related requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.