Back to skill

Security audit

Fhir R6 Guardrails

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for FHIR guardrails, but it handles clinical data and forwards upstream queries while overclaiming some security guarantees, so users should review it before use.

Before installing, confirm where upstream FHIR queries are sent, whether query parameters can contain PHI, what logs are retained, and whether audit records are actually tamper-evident in your deployment. Treat the advertised immutability and compliance protections as claims to verify, not guarantees from the inspected artifact.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill claims an 'append-only' and 'database-level immutable' audit trail, but elsewhere states local mode uses SQLite JSON blob storage. SQLite alone does not provide strong immutability guarantees, so operators may rely on audit logs for compliance or incident response when those logs could be altered or deleted by a sufficiently privileged actor.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation says that in upstream proxy mode, all query parameters are forwarded to the upstream server without an explicit warning about external transmission of clinical query data. In this healthcare context, query parameters can contain patient identifiers, codes, and other sensitive metadata, so silent forwarding can leak PHI or tenant-sensitive information to third parties or less-trusted infrastructure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says the skill provides '14 MCP tools' at L010, while the detailed tool list header says 'MCP Tools Available (12)' at L032 and the tables enumerate 12 tools total. This creates a description-behavior mismatch in the documented scope of the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.