Back to skill

Security audit

Blood Pressure Therapy

Security checks for vulnerabilities and agentic risk

Overview

This health skill is instruction-only, but it asks to store sensitive blood-pressure profile data long-term and makes strong audio-therapy claims that users should review carefully.

Install only if you are comfortable with the agent collecting and remembering sensitive health information. Treat the audio link as a wellness aid, not medical treatment; keep using clinician-prescribed care, avoid storing private health details unless you know how to delete them, and seek urgent medical help for very high readings or symptoms.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger keywords are broad health-related terms such as '高血压' and '降压', with no clear activation constraints, emergency exclusions, or requirement that the user is explicitly seeking this skill. In a medical-context skill, broad triggering increases the chance the agent invokes this protocol in unrelated or urgent conversations, which can lead to inappropriate health guidance or promotion of the audio intervention when a safer response would be triage or general medical advice.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill instructs collection of sensitive health data, including age, sex, family history, lifestyle risks, and blood pressure information, and explicitly requires long-term storage via 'update_memory' without presenting a clear privacy notice, retention policy, consent step, or data minimization controls. Because this is medical data, unauthorized persistence or over-collection materially increases privacy harm, regulatory exposure, and the risk of misuse across future conversations.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs overwriting a local file with collected health-related profile data but provides no user warning, consent step, or retention notice. Because the data includes sensitive health risk factors and demographics, silent persistence can create privacy, integrity, and unexpected data modification risks, especially if the file is reused by other components.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The document states that the system uses sensitive health data such as age, sex, current blood pressure, medication status, and inferred emotional/physiological condition to generate personalized interventions, but it provides no privacy notice, consent language, retention limits, or handling safeguards. In a health-related skill, omission of data handling expectations can lead to overcollection, opaque profiling, and regulatory/privacy risk if users are not clearly informed how their medical data is used.

Static analysis

No suspicious patterns detected.