T09 · Insecure Skill Coding Practices
- Location
scripts/gen_initial_record.py:22- Finding
Raw Medical Dialogue Is Transmitted Without Promised De-identification
- Content
View full analysis
Vulnerability Details
File Location:
scripts/gen_initial_record.py:22-26, 80-84
Related Documentation:SKILL.md:32-34
Vulnerability Type: Sensitive medical information disclosure caused by missing de-identification controls
Risk Level: HighVulnerable Code
python payload = { "diag_id": diag_id, "dep_time": datetime.now().strftime("%Y-%m-%d %H:%M:%S"), "diag": dialogue, } try: data_bytes = json.dumps(payload, ensure_ascii=False).encode("utf-8")python with open(input_path, "r", encoding="utf-8") as f: dialogue_text = f.read() print(f"Generating initial visit record from dialogue: {input_path}") # Directly call the medical-record generation API record_text = call_record_api( diag_id=diag_id, dialogue=dialogue_text, timeout=timeout, )The request is subsequently transmitted to the fixed external endpoint through
urllib.request.urlopen()atscripts/gen_initial_record.py:35-37.Technical Analysis
The skill documentation states at
SKILL.md:32-34that personally identifiable information will be removed before content is sent to any model or API. It specifically identifies names, identity numbers, phone numbers, detailed addresses, and similar information as data that will be de-identified.The implementation does not enforce this guarantee. It reads the complete dialogue file into
dialogue_text, passes that string unchanged tocall_record_api(), assigns it directly to the outbounddiagproperty, and sends the resulting JSON to:text https://shangbao.yunzhisheng.cn/skills/record-gen/gen_record_by_diag_v1No local redaction, identifier detection, data minimization, user confirmation, or residual-sensitive-data validation occurs before transmission. HTTPS protects data in transit but does not prevent the receiving service from accessing the raw medical dialogue.
Because doctor-patient dialogue may contain both health information and direct identifiers, the missing ...[truncated 1734 chars]
- Remediation
View remediation
Remediation Suggestions
- Implement local de-identification before constructing the outbound payload. At minimum, detect and replace names, phone numbers, identity numbers, email addresses, detailed addresses, and other direct identifiers.
- Treat de-identification as a mandatory security boundary rather than an optional preprocessing step. Do not send the request if sanitization fails or if high-confidence identifiers remain.
- Use a structured pipeline in which only the sanitized value can be passed to
call_record_api(); avoid retaining an API that accepts arbitrary raw dialogue. - Add automated tests that intercept outbound requests and verify that representative identifiers never appear in the request body.
- Obtain explicit informed consent before transmitting medical data to the external service, and clearly identify the recipient, purpose, retention policy, and applicable data-handling terms.
- Minimize metadata by validating whether
diag_idand the precise timestamp are necessary. Use a non-identifying, per-request random identifier when correlation is not required. - Apply a finite, secure default network timeout instead of waiting indefinitely.
- Update
SKILL.mdso its privacy claims precisely match the implemented and independently verified controls. - Consider processing the dialogue locally when privacy requirements prohibit third-party disclosure.
