Back to skill

Security audit

hash health

Security checks for vulnerabilities and agentic risk

Overview

This Hash Health skill is purpose-aligned but needs review because it can send and save sensitive food or health data before the user confirms each action.

Install only if you are comfortable with food photos, meal text, nutrition questions, and medication-related data being sent to Hash Health through the configured endpoint. Be especially careful with casual food or health statements, because the skill may log or process them without a separate confirmation step.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:15
Finding

Automatic Transmission of Sensitive Health Data Without Per-Action Consent

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15–22; related authentication and remote-service configuration at lines 34–47
Vulnerability Type: Non-consensual sensitive health-data transmission
Risk Level: Medium

Vulnerable Code

markdown
**Food image received** (user sends a photo):
1. Call `hash_upload_image` immediately with the image — do NOT describe or ask first
2. Call `detectIngredients` with your visual analysis as text parameters
3. Show detected ingredients from the tool result — ask "Confirm to save, or edit?"
4. After user confirms → call `analyze_food` with `image_path` from step 1

**Food text received** ("I ate X", "log X", "save X"):
- Call `hash_analyze_and_log` immediately — no asking first

The operations are sent to the following external service:

markdown
## Auth check

Before any request call `hash_get_daily_nutrition` with no arguments. If auth error → tell user:
> "Set your `HASH_HEALTH_TOKEN` in OpenClaw settings. Get it from Hash Health app → Settings → Advanced → Generate API Key."

---

## Setup

POST https://hash-claude-mcp.vercel.app/api/mcp Authorization: Bearer $HASH_HEALTH_TOKEN Content-Type: application/json Accept: application/json, text/event-stream

text

Technical Analysis

The skill explicitly directs the agent to upload food images and submit textual meal information to an external service immediately, while prohibiting the agent from asking for confirmation first. Food images, dietary history, meal descriptions, nutrition questions, and medication records can constitute sensitive personal or health-related information.

Confirmation occurs only after the image has already been uploaded and analyzed. It therefore controls whether the final analyzed meal is saved, but it does not control the initial disclosure of the image and inferred ingredients. For textual logging requests, hash_analyze_and_log is invoked ...[truncated 2074 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit, informed consent before the first image upload, nutrition-chat request, health-data retrieval, or account mutation.
  2. Replace instructions such as “immediately,” “do NOT ask first,” and “no asking first” with a confirmation workflow that clearly identifies:
    • The data that will be transmitted.
    • The destination service.
    • Whether the operation will save or modify account data.
  3. For image workflows, obtain consent before calling hash_upload_image, not merely before calling analyze_food.
  4. Separate analysis from persistence. Default to save: false where supported, and perform a second call with persistence enabled only after the user confirms.
  5. Narrow skill activation to explicit requests to use Hash Health rather than ordinary mentions of food, nutrition, medication, or health.
  6. Replace the daily-nutrition authentication check with a minimal authentication or account-status endpoint that does not retrieve health records.
  7. Apply data minimization by sending only fields necessary for the requested operation and avoiding unrelated health-history retrieval.
  8. Provide clear error handling and allow users to cancel before any sensitive data leaves the current environment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to upload meal photos and process health-related data immediately, but the description does not prominently warn users that this information is sent to an external service before confirmation. That is especially risky here because images, nutrition logs, and medication data are sensitive, and transmission occurs prior to any explicit consent checkpoint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation description is broad enough to trigger on general health, food, or medication discussions, which can route users into a tool that transmits sensitive health data to an external service. In this skill’s context, over-invocation is more dangerous because the tool handles nutrition and medication information, both of which are sensitive categories of personal data.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

The skill directs the agent to perform external actions immediately on receipt of food images or text, without first obtaining user confirmation at the point of transmission. In this context, that means potentially sending sensitive images and health-related meal data to a third-party-connected service and creating records automatically, which increases privacy and consent risk.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
4. After user confirms → call `analyze_food` with `image_path` from step 1

**Food text received** ("I ate X", "log X", "save X"):
- Call `hash_analyze_and_log` immediately — no asking first

**Only pause point:** After `detectIngredients` returns, show the list and wait for "yes/save/looks good" before calling `analyze_food`.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

The instruction to call hash_analyze_and_log immediately for phrases like 'I ate X' or 'track X' causes autonomous external processing and persistence without a confirmation step. Because this skill handles health and dietary records, unintended logging can create privacy issues, inaccurate records, and unauthorized transmission of sensitive personal information.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

Log a meal — from text

Trigger: "log X", "I ate X", "save X", "track X" — call immediately, no asking.

json
{

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example for text meal logging hard-codes "language": "en", which imposes a specific language setting without offering the user a choice. This is a natural-language policy concern because the file does not document any locale-specific requirement or opt-in for English-only behavior.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 402)May include surrounding context.

md
- Never guess a meal UUID or medication ID — look it up first.
- Always confirm before deleting.
- Medication `id` is a number — not a string.
- Never ask the user to paste their token in chat — always use OpenClaw environment settings.
- If token is missing/invalid: "Set your `HASH_HEALTH_TOKEN` in OpenClaw settings. Hash Health app → Settings → Advanced → Generate API Key."

Static analysis

No suspicious patterns detected.