Back to skill

Security audit

Automated Soap Note Generator

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate SOAP note drafting skill, but it should be reviewed because it can save sensitive patient information locally and some examples blur into clinical treatment guidance.

Install only for use in a HIPAA-compliant or otherwise approved clinical environment. Treat every output as an unverified draft, avoid JSON export unless retaining raw input and identifiers is acceptable, choose protected output paths, and do not use the examples as treatment guidance or for psychiatric/diagnostic/medication decisions without licensed clinician review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
This reference file presents medical abbreviations, medications, conditions, and treatment-oriented language without any inline disclaimer that it is informational terminology only and not clinical guidance. In a medical documentation skill, users or downstream components could over-rely on the content as authoritative care advice, increasing the risk of inappropriate documentation suggestions or unsafe clinical inferences despite the broader skill-level warning.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The file provides realistic clinical examples that include diagnoses, medications, dosing, and treatment plans, but the examples themselves do not carry an explicit warning that they are illustrative drafts only and must not be used as medical advice or copied into records without clinician verification. In a healthcare documentation skill, users may over-trust polished examples and treat them as approved care patterns, which can propagate unsafe or inappropriate clinical guidance when applied outside the narrow sample context.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The script writes generated SOAP notes containing raw clinical text, extracted entities, patient identifiers, and provider information directly to an output file with no safeguards around storage location, permissions, encryption, redaction, or user warning. In a medical-documentation context, this creates a real confidentiality risk because PHI may be persisted to disk insecurely and exposed through shared directories, backups, logs, or accidental file handling.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.