T09 · Insecure Skill Coding Practices
- Location
scripts/struct_followup_record.py:61- Finding
Raw Medical Records Are Transmitted to an External Service Without De-identification
- Content
View full analysis
Vulnerability Details
File Location:
scripts/struct_followup_record.py:61-70
Related Documentation:SKILL.md:38-40
Vulnerability Type: Sensitive medical-data disclosure to a third party
Risk Level: HighVulnerable Code
python payload: Dict[str, Any] = { "his_record": his_record, "diag_id": diag_id or "skill-diag", } if department: payload["department"] = department body = _post_json(API_URL, payload, timeout=timeout)The relevant privacy guarantee in
SKILL.mdstates that identifiable information will be de-identified before being sent to any model or API. However, the implementation contains no de-identification step.Technical Analysis
The complete contents of the input medical record are assigned directly to the
his_recordrequest field and transmitted to the hard-coded external endpoint:text https://shangbao.yunzhisheng.cn/skills/record-struct/gen_abstract_by_hisNo local filtering, identifier detection, redaction, data minimization, consent check, or validation occurs before transmission. Consequently, any names, identification numbers, telephone numbers, addresses, visit identifiers, diagnoses, treatment details, or other sensitive information in the source file may be disclosed to the remote service.
HTTPS protects the request in transit against ordinary passive interception, but it does not prevent the receiving service from accessing, retaining, or further processing the record. The implementation also does not expose controls for selecting which medical-record fields may be transmitted.
Attack Path
- A user provides a follow-up record containing personal or sensitive medical information.
struct_followup_record()reads the entire input file intorecord_text.call_followup_struct_api()places the unmodified text intopayload["his_record"]._post_json()sends the full payload to the hard-coded external ser ...[truncated 913 chars]
- Remediation
View remediation
Remediation Suggestions
- Implement local de-identification before constructing the HTTP payload. At minimum, detect and redact names, government identifiers, telephone numbers, email addresses, detailed addresses, medical-record numbers, and other direct identifiers.
- Reject transmission when identifier detection finds unresolved sensitive values, unless the user gives informed and explicit consent.
- Apply data minimization by transmitting only fields required for structuring rather than an unrestricted source document whenever practical.
- Clearly identify the external processor, its purpose, retention policy, data-processing terms, and geographic or regulatory implications.
- Add automated tests containing representative identifiers to verify that raw values never reach
_post_json(). - Consider an entirely local processing mode for records that cannot legally or contractually be sent to an external processor.
- Update the documentation so that it accurately reflects the implemented privacy controls and does not promise de-identification until that control is verifiably present.
