Back to skill

Security audit

Medical Report Query

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for medical reporting, but it can steer an agent toward querying sensitive patient, billing, insurance, and pharmacy data with broad triggers and limited safeguards.

Install only in an environment where the agent has authorized, least-privilege access to the relevant medical databases. Require confirmation before queries, mask patient and billing identifiers by default, restrict exports, and ensure normal healthcare privacy, audit, and recipient controls are in place.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger words are very broad generic terms such as '報表', '查詢', and '統計', which are likely to activate in ordinary workplace or medical conversations. In a healthcare context, unintended activation can route routine discussion into a skill that performs database-backed reporting, increasing the chance of exposing sensitive operational, insurance, or patient-related data without deliberate user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill is explicitly designed to query outpatient, inpatient, drug, and insurance reporting data, all of which can contain highly sensitive medical and financial information. The documentation does not clearly warn users that generated queries and reports may expose protected health information or insurance data, which increases the likelihood of unsafe use, overbroad requests, and disclosure to unauthorized recipients.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

All user-facing content and examples are presented only in Traditional Chinese, and the description does not state that the skill is region-specific or provide language options. Under the stated policy, a fixed language without opt-in or justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.