Back to skill

Security audit

Unstructured Medical Text Miner

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate medical text-mining tool, but it handles sensitive clinical notes and writes outputs without enough privacy and filesystem safeguards.

Install and run this only in an environment approved for clinical data. Treat both source notes and generated JSON as sensitive health information, restrict output locations, avoid absolute or traversal output paths, and pin/audit dependencies before use in production or regulated workflows.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:497
Finding

Arbitrary Output Path Permits Overwriting Files Accessible to the Runtime User

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares executable Python scripts and explicit output-file writing behavior, but it does not define any tool scope such as allowed-tools or permissions. That omission can cause an agent runtime to grant broader filesystem capabilities than the skill actually needs, increasing the chance of unintended writes or misuse if inputs are manipulated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill is designed to process unstructured clinical notes from MIMIC-IV and produce extracted outputs, but the user-facing documentation does not prominently warn that the inputs and outputs may contain sensitive medical data. In a medical-text-mining context, that increases the risk of operators handling PHI or re-identifiable data insecurely, saving raw text to disk, or sharing derived outputs without appropriate controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The example explicitly demonstrates loading, processing, and exporting patient-derived MIMIC-IV notes to JSON without any user-facing warning about handling sensitive clinical data, de-identification limits, or downstream disclosure risk. Even though MIMIC-IV is controlled and de-identified, extracted insights can still contain sensitive medical content and may be re-exported or combined with other data in unsafe ways, making this a real privacy hygiene issue in a medical-text-mining skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code loads and processes patient note data from CSV/Parquet with no visible privacy notice, access-control checks, or handling constraints despite operating on clinical free text. In this context, silent ingestion of sensitive health records makes accidental misuse more likely, especially by users who may not appreciate that downstream extraction and reporting can preserve regulated medical information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script writes extracted patient insights directly to a JSON file, and those insights can include raw note-derived entities, timelines, and clinical logic tied to subject and admission identifiers. In a medical-data mining skill operating on MIMIC-IV-style notes, exporting without explicit safeguards, de-identification, consent checks, or strong warnings materially increases the risk of sensitive health information being stored insecurely or mishandled downstream.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The configuration specifies English SciSpaCy models such as "en_core_sci_lg", which imposes an English-language processing assumption. The skill does not clearly present this as a user-selectable locale or explicitly justify that it is limited to English-language clinical text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest contains operational comments and guidance in Chinese across multiple sections, while other identifiers and labels remain in English. Because the file provides no stated language preference, opt-in, or locale-specific justification, it may violate a policy requiring user-facing skill materials to avoid forcing a specific language without consent.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency negspacy is declared without any version constraint, making builds non-reproducible and allowing future installs to pull in unexpected or vulnerable releases. In a medical-text processing skill, this increases supply-chain risk because behavior and security posture can change between deployments without review.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
negspacy
numpy
pandas
pyarrow

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
99% confidence
Finding

numpy is unpinned, so the environment may resolve to different versions over time, including releases with known defects or advisories. This is a supply-chain hygiene issue rather than an immediate exploit by itself, but it weakens assurance over what code is actually installed.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
negspacy
numpy
pandas
pyarrow
pyyaml

Unverifiable Dependency: numpy has 16 known advisory(ies) (CVE-2014-1859 (Numpy arbitrary file write via symlink attack); CVE-2021-41495 (NumPy NULL Pointer Dereference); CVE-2021-33430 (NumPy Buffer Overflow (Disputed)) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The manifest does not pin numpy, and numpy has known advisories across some versions, so it is impossible to verify whether deployments are affected. This is dangerous because the actual installed package may vary by time and environment, defeating security review and patch assurance.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
99% confidence
Finding

pandas is listed without a version, which means installations are not reproducible and may silently introduce vulnerable or incompatible releases. For software mining unstructured clinical text, unexpected dependency changes can affect both security and data-processing integrity.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
negspacy
numpy
pandas
pyarrow
pyyaml
scispacy

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

Because pandas is not version-pinned and has at least one known advisory in certain releases, the project cannot demonstrate that installed environments are safe. In data-processing pipelines, this uncertainty can propagate across research or operational systems and complicate incident response.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
99% confidence
Finding

pyarrow is unpinned, exposing the project to accidental installation of versions with known vulnerabilities or risky parsing behavior. Given that pyarrow often handles complex file formats, uncontrolled version drift is more concerning than for a purely utility package.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
negspacy
numpy
pandas
pyarrow
pyyaml
scispacy
spacy

Unverifiable Dependency: pyarrow has 9 known advisory(ies) (CVE-2023-47248 (PyArrow: Arbitrary code execution when loading a malicious data file); CVE-2019-12408 (Missing Initialization of Resource in Apache Arrow); CVE-2019-12410 (Missing Initialization of Resource in Apache Arrow) +6 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
96% confidence
Finding

pyarrow has advisories including issues related to loading malicious data, but the lack of version pinning means the deployment could inadvertently install an affected release. In a skill that may process large structured or semi-structured datasets, this uncertainty is more dangerous because file-parsing libraries often sit on attacker-influenced input boundaries.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
99% confidence
Finding

pyyaml is unpinned, which is risky because some PyYAML versions have had unsafe deserialization issues. If the broader skill ever parses YAML from untrusted or semi-trusted sources, an unreviewed upgrade or downgrade could materially increase exploitability.

Content

Scanner excerpt · requirements.txt (reported line 5)May include surrounding context.

text
numpy
pandas
pyarrow
pyyaml
scispacy
spacy
tqdm

Unverifiable Dependency: pyyaml has 8 known advisory(ies) (CVE-2019-20477 (Deserialization of Untrusted Data in PyYAML); CVE-2020-1747 (Improper Input Validation in PyYAML); CVE-2020-14343 (Improper Input Validation in PyYAML) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
98% confidence
Finding

PyYAML has a history of unsafe deserialization vulnerabilities, and without pinning there is no reliable way to know whether a deployed environment uses a safe release. If any component of the skill ingests YAML configuration or data from untrusted sources, this could become a code-execution path.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

scispacy is unpinned, so future installations may bring in different dependency trees and behavior without validation. While not inherently a direct exploit, this weakens supply-chain control in a package used for processing sensitive clinical text.

Content

Scanner excerpt · requirements.txt (reported line 6)May include surrounding context.

text
pandas
pyarrow
pyyaml
scispacy
spacy
tqdm

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

spacy is unpinned, which can result in unpredictable installs and potential exposure to newly introduced vulnerabilities or breaking changes. NLP frameworks can also pull substantial transitive dependencies, increasing overall supply-chain uncertainty.

Content

Scanner excerpt · requirements.txt (reported line 7)May include surrounding context.

text
pyarrow
pyyaml
scispacy
spacy
tqdm

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

tqdm is unpinned, so an install may resolve to a version with known issues or unexpected behavior. Even though it is primarily a utility library, leaving it unconstrained still contributes to preventable supply-chain exposure.

Content

Scanner excerpt · requirements.txt (reported line 8)May include surrounding context.

text
pyyaml
scispacy
spacy
tqdm

Unverifiable Dependency: tqdm has 4 known advisory(ies) (CVE-2024-34062 (tqdm CLI arguments injection attack); CVE-2016-10075 (TDQM Arbitrary Code Execution); CVE-2016-10075 (The tqdm._version module in tqdm versions 4.4.1 and 4.10 allows local users to e) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

tqdm has known advisories affecting some versions, and the absence of a version pin prevents verification that the installed package is not affected. Although tqdm is not central to clinical text mining logic, unverifiable utility dependencies still increase supply-chain uncertainty and can introduce avoidable risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.