Back to skill

Security audit

Fhir R6 Guardrails

Security checks across malware telemetry and agentic risk

Overview

The skill appears purpose-aligned, but upstream FHIR proxy mode can forward sensitive health query details to an external server.

Before installing, confirm whether you will use upstream proxy mode. If so, treat query parameters as potentially sensitive health data, allowlist only trusted FHIR servers, and do not send real patient data unless your privacy, consent, and contractual requirements are satisfied.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill documentation acknowledges that in upstream proxy mode all query parameters are forwarded to an external FHIR server, but it does not prominently warn users in the skill description or usage guidance about the resulting privacy and data-handling implications. In a healthcare context, forwarded query parameters can contain patient references, codes, dates, and other sensitive metadata, so omission of an explicit warning can lead operators or agents to send regulated data to third-party systems without informed consent or proper configuration review.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.