Back to skill

Security audit

Wellally Health Skills

Security checks for vulnerabilities and agentic risk

Overview

This health skill suite is not overtly malicious, but it needs review because it broadly reads and stores sensitive medical data, gives high-stakes health guidance, and generated reports load third-party scripts.

Review before installing. Use this only in an environment where local medical files are expected to be read and written, avoid opening generated reports while online unless remote scripts are removed or pinned with integrity checks, and do not rely on the skill for diagnoses, medication changes, pediatric dosing, emergency triage, pregnancy decisions, or mental-health crisis handling. Prefer explicit consent, no-history mode, deletion controls, and local-only bundled report assets before broad use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
skills/report/SKILL.md:80
Finding

Remote Third-Party JavaScript Executes Within Sensitive Health Reports

Content
View full analysis
健康报告 - {生成日期} ``` ### Technical Analysis The report skill collects patient profile, biochemical, imaging, medication, radiation, allergy, symptom, surgery, and discharge information before generating an HTML report. The generated document then downloads and executes JavaScript from three external CDN origins. The Tailwind URL has no explicit version, while the Lucide URL deliberately uses the mutable `latest` release. None of the resources includes a Subresource Integrity hash. Therefore, the effective code executed when a report is opened can change after the skill has been reviewed. Remote scripts execute in the report's browser document and can access its DOM, including embedded medical information. If a CDN, upstream package, maintainer account, DNS route, or delivery infrastructure is compromised, malicious JavaScript could read the report and issue outbound requests containing its contents. The behavior is not required at this privilege level. Health reports can use locally bundled, reviewed assets or static styles and charts without granting mutable third-party code access to sensitive report content. ### Attack Path 1. A user invokes the report skill. 2. The skill reads local health records and embeds selected patient information in an HTML report. 3. The user opens the generated report in a browser. 4. The browser requests scripts from `cdn.tailwindcss.com`, `cdn.jsdelivr.net`, and `unpk ...[truncated 927 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (406)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The configuration enables explicit 10-year health risk prediction models for hypertension, diabetes, and cardiovascular disease while the safety policy states that prognosis is prohibited. In a health-related skill, this contradiction can lead the system to generate forward-looking medical inferences that users may reasonably interpret as prognostic guidance, undermining safety controls and increasing risk of harmful self-management decisions.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · skills.md (reported line 34)May include surrounding context.

text
  </Step>

  <Step title="Write SKILL.md">
    Every skill needs a `SKILL.md` file with two parts: YAML frontmatter (between `---` markers) that tells Claude when to use the skill, and markdown content with instructions Claude follows when the skill is invoked. The `name` field becomes the `/slash-command`, and the `description` helps Claude decide when to load it automatically.

    Create `~/.claude/skills/explain-code/SKILL.md`:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill is explicitly designed to process highly sensitive health information, yet it provides no privacy, consent, retention, or data-handling warning. That omission is dangerous because users may not realize medical and lifestyle data will be aggregated across sources, analyzed, and potentially exposed in outputs, creating confidentiality and compliance risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The examples provide pediatric fever-medication thresholds and dosing ranges in a way that can be interpreted as actionable medical advice, but they do not prominently warn users to verify dosing with a clinician, use the product concentration, or account for contraindications and child-specific factors. In a child-health context, missing safeguards can lead to overdosing, inappropriate drug selection, delayed care, or reliance on the skill instead of professional medical guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The hypoglycemia example gives concrete emergency-style management instructions such as taking glucose and re-checking after 15 minutes, but it does not clearly warn that this is not a substitute for clinician guidance or urgent medical care. In a diabetes-management skill, users may rely on the instructions during an acute event, and missing escalation guidance could delay appropriate care for severe or worsening hypoglycemia.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill directs copying discharge images, generating structured JSON, and updating a global index for highly sensitive medical information without any privacy notice, minimization guidance, retention policy, or consent step. This risks unauthorized persistence and aggregation of protected health information, increasing exposure from accidental disclosure, overcollection, or insecure storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that every conversation automatically loads and analyzes all health data, but it does not present a prominent upfront warning to the user that sensitive medical records may be accessed on each invocation. This undermines informed consent and data minimization, especially because health data is a highly sensitive category whose unnecessary processing can create privacy and compliance risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow mandates reading all health data for every conversation regardless of necessity and includes retention of conversation content, violating least-privilege and data-minimization principles. In a health assistant, this creates unnecessary aggregation of sensitive information, expanding the blast radius of any misuse, prompt injection, accidental disclosure, or local file exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The conversation history section describes saving sensitive medical conversations, including original user input and derived metadata, without a clear retention notice or explicit user consent. Persistent storage of health-related conversations materially increases exposure if the history file is later accessed, reused, or mishandled.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The logging schema persists original health-related user inputs, data sources used, and summaries in a history file, creating a durable record of sensitive medical interactions. Even if intended for convenience, storing detailed medical prompts and associated metadata increases privacy harm and secondary-use risk far beyond what is needed to answer a single conversation.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document says conversation history is automatically saved to a file containing user input, intent, data sources, summaries, and follow-up suggestions, yet it does not clearly warn users that sensitive health discussions will persist. Persistent storage of medical conversations materially raises confidentiality and compliance risk because highly sensitive data may remain accessible beyond the immediate session and could be reused or disclosed unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill persists sensitive medical data, including blood pressure and organ-assessment information, to a local file without any user-facing notice, consent flow, retention policy, or storage safeguards. Health data is highly sensitive, so silent persistence materially increases privacy and confidentiality risk if the device, workspace, or file system is shared or later exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill stores highly sensitive reproductive and hormone data to local files but does not present a clear, upfront privacy warning or explicit consent step before collection and persistence. Because this is intimate medical information, silent or unclear storage materially raises confidentiality and compliance risk if the device, workspace, or repository is shared or later exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The missed-dose example gives a concrete timing rule without any warning to verify with a clinician, pharmacist, or official medication instructions. This is especially risky in the context of a medication skill because users are likely to rely on the output as actionable health guidance, and an incorrect missed-dose recommendation can cause overdose, underdose, or adverse events.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs saving highly sensitive mental-health information, including assessments, therapy records, and crisis-plan data, to a local file without explicit informed consent or a privacy warning. This creates a substantial confidentiality risk because deeply personal health data may be persisted unexpectedly, exposed to other local users/processes, or retained longer than the user realizes.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example includes PHQ-9 item 9 with a non-zero self-harm indicator and only responds with a mild note to monitor mood changes, without immediate safety messaging, crisis escalation, or guidance to seek urgent human help. In a mental-health skill, this omission is dangerous because example outputs strongly shape runtime behavior and may normalize under-reacting to potential self-harm risk.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The onboarding flow is configured to trigger on any first user message whenever the settings file is missing or onboarding is incomplete. This broad trigger can override the user's intended action, cause unexpected state creation, and prompt for collection of personal profile data before the user explicitly requests onboarding, which is a security and privacy design weakness.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly claims it cannot adjust doses or suggest stopping medications, yet it provides a concrete week-by-week diazepam taper schedule and named switch/discontinue actions. In a medication-management context, this creates actionable medical instructions that users could follow without clinician oversight, increasing the risk of withdrawal, adverse events, or unsafe substitution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This example shows the skill making a diagnostic-style determination ('Diagnosis: Gestational Diabetes') from user-provided values and then issuing treatment-oriented recommendations. In a pregnancy context, users may rely on the output as clinical decision support, and without explicit scope limits, validation, or clinician oversight, incorrect interpretation could delay proper care or cause harmful self-management.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

These examples provide emergency triage and immediate-care directives based on reported blood pressure and symptoms, which is high-stakes medical guidance. In a pregnancy skill, users may act on or ignore urgent conditions based on the model's wording, so unsupported triage logic can lead to delayed emergency evaluation or false reassurance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

AI analysis, personalization, natural-language interaction, and multiple sensitive health data sources are broadly enabled with no clear invocation boundaries, authorization gates, or feature-specific trigger conditions. In a health context, over-broad activation increases the chance of unnecessary processing of sensitive data, accidental feature invocation, and policy-violating outputs across analysis and reporting workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This JSON manifest/data file identifies the dataset as "china_2025" and describes it entirely in Chinese, which imposes a specific locale and language in natural-language content. Under the policy rule, locale constraints should either offer user choice or be explicitly documented as region-specific and justified; this file does not provide that explanation within the content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON manifest/content names and describes the skill exclusively in Chinese, and the recommendations throughout the file are also provided only in Chinese. Because the file does not document that the language is optional, user-selected, or justified as region-specific, it may violate a language/locale policy requiring choice or explicit constraint disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON file includes multiple hard-coded Chinese path names such as "周期记录", "经期症状", and similar localized directory labels. Because SQP-3 applies to all file types and there is no indication here that users can choose locale or that the Chinese-only naming is justified as region-specific, this creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

SQP-3 applies to all file types and covers natural-language policy violations such as forcing a specific language without user opt-in. This file contains user-facing medical descriptions, recommendations, and the disclaimer exclusively in Chinese, with no nearby note that the skill is China-specific or that users can choose another language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.