Back to skill

Security audit

critical-disease-review

Security checks for vulnerabilities and agentic risk

Overview

This medical-claims skill has a coherent purpose, but it under-discloses sensitive health-data transmission and writes assessment results to disk despite privacy claims saying it will not.

Review before installing or using with real patient or claims data. Require endpoint approval, explicit consent, field minimization or redaction, and corrected documentation. Do not rely on the stated no-persistence/de-identification guarantees until the implementation enforces them and default disk writes are removed or made opt-in with retention controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/major_disease_assess.py:79
Finding

Unredacted medical records are transmitted to an external service contrary to documented privacy guarantees

Content
View full analysis
None: if not isinstance(payload, dict): raise ValueError("payload must be a JSON object") if "medicalRecord" not in payload or not isinstance(payload["medicalRecord"], dict): raise ValueError("Missing or invalid key: medicalRecord (object).") mr = payload["medicalRecord"] docs = mr.get("docs") if not isinstance(docs, list) or len(docs) == 0: raise ValueError("medicalRecord.docs must be a non-empty list.") has_doc_type = any(isinstance(d, dict) and d.get("docType") for d in docs) if not has_doc_type: raise ValueErr ...[truncated 2855 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/major_disease_assess.py:126
Finding

Sensitive assessment results are persisted to disk despite a no-persistence claim

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill states that no local persistent storage is used and that data is destroyed after the call, but later documents output paths that save raw JSON responses and text conclusions to local files. For medical claims data, this contradiction is dangerous because it can leave sensitive health information on disk, increasing exposure through logs, backups, or unauthorized file access.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
- **发布约束**:示例输入、运行输出、自测脚本均放在 skill 包外(分别位于 `../data/`、`../runs/`、`../self_tests/`),skill 目录内仅保留可发布的核心文件(`scripts/`、`SKILL.md`、`_meta.json`)。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documentation advertises capabilities that imply reading files, writing files, and making network requests, but it does not declare any explicit tool scope or permissions boundary. In a medical-claims context handling sensitive records, missing scope declarations increases the chance of over-broad execution and unauthorized access to local data or internal services.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document claims strict de-identification before sending data to any model or interface, yet the skill description says it submits hospitalization medical-record data to an internal assessment API. If the implementation follows the latter without enforced redaction, sensitive medical and personal data could be disclosed contrary to the stated privacy guarantees, creating serious compliance and confidentiality risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's natural-language output and inline documentation are explicitly Chinese, and the generated user-facing strings throughout the file are hard-coded in Chinese. For an all-file-types policy review, this is a language/locale constraint without any user opt-in or documented justification for why output must be Chinese.

Content

No source excerpt is available for this finding.

Tainted flow: 'text' from pathlib.Path.read_text (line 85, file read) → pathlib.Path.write_text (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/format_assessment_nl.py (reported line 90)May include surrounding context.

python
if args.output:
        out_path = Path(args.output)
        out_path.parent.mkdir(parents=True, exist_ok=True)
        out_path.write_text(text, encoding="utf-8")
    else:
        print(text)
    return 0

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script transmits structured medical record data to a remote network endpoint containing highly sensitive health information, but provides no explicit user warning, consent flow, destination transparency, or data-handling notice. In this skill context, the data is medical/insurance-related PHI, so silent transmission to an internal or third-party service materially increases privacy, compliance, and unauthorized disclosure risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

Natural-language strings such as 重大疾病 and the imported formatter build_natural_language indicate locale-specific behavior, but the script provides no opt-in or configurable language selection. Under the policy, forcing a specific language without user choice can be a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language instructions, parameter explanations, and operational guidance are presented only in Chinese. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation unless the constraint is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.