Back to skill

Security audit

医生工作台助手 (Agentic AI 科研平台)

Security checks for vulnerabilities and agentic risk

Overview

This doctor-assistant skill is narrowly scoped to reading one demo patient data file and posting limited local status updates, with no evidence of persistence, credential access, or destructive behavior.

Before installing, confirm that http://localhost:5001/api/report is an intended local reporting service and that it will not log or forward sensitive patient content. The skill should remain acceptable for demo use, but avoid adapting the reporting payload to include patient identifiers, notes, lab details, or clinical summaries without explicit consent and controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill performs HTTP POST reporting to a local endpoint during execution, but the skill description does not warn the user that workflow activity related to a patient-facing medical task is transmitted externally. In a healthcare context, even status messages can reveal that a patient-related review is occurring, and future modifications could easily expand the payload to include sensitive data without user awareness.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill issues an HTTP POST to a local reporting service, creating an external transmission path outside the core patient-summary function. Although the current payload appears limited to status metadata, the medical context increases sensitivity because the action is tied to patient-case handling, and localhost services may be proxied, logged, or accessed by other local components.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

1. 上报开始

bash
curl -s -X POST http://localhost:5001/api/report \
  -H "Content-Type: application/json" \
  -d '{"skill":"doctor-assistant","display_name":"医生工作台助手","status":"running","message":"正在整理患者摘要、时间线与检验趋势..."}'

Static analysis

No suspicious patterns detected.