other
- Location
SKILL.md:15- Finding
Automatic Transmission of Sensitive Health Data Without Per-Action Consent
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15–22; related authentication and remote-service configuration at lines 34–47
Vulnerability Type: Non-consensual sensitive health-data transmission
Risk Level: MediumVulnerable Code
markdown **Food image received** (user sends a photo): 1. Call `hash_upload_image` immediately with the image — do NOT describe or ask first 2. Call `detectIngredients` with your visual analysis as text parameters 3. Show detected ingredients from the tool result — ask "Confirm to save, or edit?" 4. After user confirms → call `analyze_food` with `image_path` from step 1 **Food text received** ("I ate X", "log X", "save X"): - Call `hash_analyze_and_log` immediately — no asking firstThe operations are sent to the following external service:
markdown ## Auth check Before any request call `hash_get_daily_nutrition` with no arguments. If auth error → tell user: > "Set your `HASH_HEALTH_TOKEN` in OpenClaw settings. Get it from Hash Health app → Settings → Advanced → Generate API Key." --- ## SetupPOST https://hash-claude-mcp.vercel.app/api/mcp Authorization: Bearer $HASH_HEALTH_TOKEN Content-Type: application/json Accept: application/json, text/event-stream
text Technical Analysis
The skill explicitly directs the agent to upload food images and submit textual meal information to an external service immediately, while prohibiting the agent from asking for confirmation first. Food images, dietary history, meal descriptions, nutrition questions, and medication records can constitute sensitive personal or health-related information.
Confirmation occurs only after the image has already been uploaded and analyzed. It therefore controls whether the final analyzed meal is saved, but it does not control the initial disclosure of the image and inferred ingredients. For textual logging requests,
hash_analyze_and_logis invoked ...[truncated 2074 chars]- Remediation
View remediation
Remediation Suggestions
- Require explicit, informed consent before the first image upload, nutrition-chat request, health-data retrieval, or account mutation.
- Replace instructions such as “immediately,” “do NOT ask first,” and “no asking first” with a confirmation workflow that clearly identifies:
- The data that will be transmitted.
- The destination service.
- Whether the operation will save or modify account data.
- For image workflows, obtain consent before calling
hash_upload_image, not merely before callinganalyze_food. - Separate analysis from persistence. Default to
save: falsewhere supported, and perform a second call with persistence enabled only after the user confirms. - Narrow skill activation to explicit requests to use Hash Health rather than ordinary mentions of food, nutrition, medication, or health.
- Replace the daily-nutrition authentication check with a minimal authentication or account-status endpoint that does not retrieve health records.
- Apply data minimization by sending only fields necessary for the requested operation and avoiding unrelated health-history retrieval.
- Provide clear error handling and allow users to cancel before any sensitive data leaves the current environment.
