Back to skill

Security audit

Share Health Qr

Security checks for vulnerabilities and agentic risk

Overview

This is a clearly scoped health-record QR sharing workflow with strong consent and privacy guardrails, and no executable install behavior in the artifact.

Install only for a configured SHL/FHIR workflow where patients intentionally share records. Confirm scope and expiry before each QR generation, treat viewer and manage links as sensitive, and do not use it as a generic QR generator for health data.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.