Back to skill

Security audit

test

Security checks for vulnerabilities and agentic risk

Overview

This Hash Health skill is purpose-aligned, but it handles identifiable meal and medication data through an external API with under-specified authentication, consent, and deletion safeguards.

Review before installing. Only use this skill if you trust the Hash Health API operator with meal, nutrition, medication, schedule, and identifier data, and ensure the agent asks for explicit confirmation before saving or deleting records. Avoid using an email address as the user ID if an opaque account ID is available.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:29
Finding

Health Record Operations Rely on a User-Controlled Identifier Without Documented Authentication

Content
View full analysis
` Display: calories, protein, carbs, fat, fiber, streak. ## Tool: View today's meals GET `https://hash-claude-mcp.vercel.app/api/unified-history?user_id={HASH_HEALTH_USER_ID}&date=&limit=20` ``` ```markdown ## Tool: List medications GET `https://hash-claude-mcp.vercel.app/api/medi-history?user_id={HASH_HEALTH_USER_ID}` ``` ```markdown ## Tool: Delete a meal DELETE `https://hash-claude-mcp.vercel.app/api/unified-history?id=&user_id={HASH_HEALTH_USER_ID}` If user gives a meal name instead of ID, first call GET /api/unified-history to find the matching entry UUID. ## Tool: Delete a medication DELETE `https://hash-claude-mcp.vercel.app/api/medi-history?id=&user_id={HASH_HEALTH_USER_ID}` If user gives a medication name instead of ID, first call GET /api/medi-history to find the matching numeric ID. ``` ### Technical Analysis All documented read and delete operations identify the account through the caller-supplied `HASH_HEALTH_USER_ID`. The skill does not document an authentication token, signed request, session credential, or other mechanism that cryptographically binds the request to the identified account. If the server implements the interface exactly as documented, changing `user_id` may be sufficient to access another account's nutrition or medication records. This is a potential insecure direct object reference and broken object-level authorization condition. The history endpoints can also disclose record identifiers that are subsequently accepted by the deletion endpoints. The user identifier may be an email address and is ...[truncated 1457 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:9
Finding

Identifiable Health Information Is Sent to an External Service Without Documented Privacy Safeguards

Content
View full analysis
\",\"is_edited_food_name\":false,\"language\":\"en\"}" } ], "language": "en" } ``` **Step 2 — Save to history** POST `https://hash-claude-mcp.vercel.app/api/unified-history` ```json { "user_id": "{HASH_HEALTH_USER_ID}", "type": "analysis", "analysis": "" } ``` ``` ```markdown ## Tool: Add medication POST `https://hash-claude-mcp.vercel.app/api/medi-history` ```json { "user_id": "{HASH_HEALTH_USER_ID}", "name": "", "dosage": "", "frequency": "", "time_of_day": ["morning", "evening"], "notes": "" } ``` ``` ### Technical Analysis The skill directs the agent to send an email or user identifier, meal information, nutrition analyses, medication names, dosages, frequencies, schedules, and notes to `hash-claude-mcp.vercel.app`. These fields can reveal sensitive health and lifestyle information and can be directly associated with an identifiable user. Transmission to the external service is consistent with the skill's declared Hash Health functionality and is not concealed exfiltration. However, the skill does not document: - Explicit informed consent before transmitting identifiable health information. - The identity or verification status of the external service operator. - Data retention, deletion, secondary-use, or privacy policies. - Authe ...[truncated 1549 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill sends identifiable and highly sensitive health data, including user ID/email, meal information, nutrition analysis, and medication records, to an external service without any explicit disclosure or consent language. In this context, undisclosed third-party transmission of health data is especially dangerous because users may not expect medical and dietary information to leave the host environment.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented meal-logging flow saves data in Step 2 and only confirms afterward, while later instructions say meal logging must always be confirmed before saving. In a health-tracking context, this can cause unauthorized or inaccurate entries to be written to a user's record before they have approved the contents.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest advertises health logging and medication management but omits that the skill can delete meals and medications. This creates a consent and transparency gap: users or orchestrators may invoke the skill without realizing it supports destructive actions on sensitive health records.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger terms are broad enough to match everyday conversation about food, eating, medications, or health, which can cause over-invocation of a skill connected to external health APIs. Because the skill can transmit sensitive health data and perform writes/deletes, accidental activation materially increases privacy and integrity risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Hard-coding English for food analysis without user choice can lead to misinterpretation of meal names, incorrect nutrition estimates, and unintended data quality issues for non-English users. While less severe than unauthorized deletion or undisclosed data sharing, it is still a reliability and consent issue in a health-related workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents destructive delete operations for meals and medications without requiring a user-facing warning that records will be permanently removed. For health data, accidental deletion can impair tracking accuracy, medication management, and user trust, especially if the skill is invoked from ambiguous requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.