Back to skill

Security audit

Dermatologist

Security checks for vulnerabilities and agentic risk

Overview

This is a local dermatology tracking skill, but it needs review because one photo rule conflicts with its stronger promise not to request or store minor or intimate-area photos.

Install only if you are comfortable with a local folder of sensitive skin-health records under ~/dermatologist/. Choose ask-first activation, approve storage only for cases you want retained, avoid storing photos or metadata for minors or intimate areas, and delete/export records directly from that folder when no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
photo-protocol.md:5
Finding

Minor Image Handling Policy Contradiction

Content
View full analysis

Vulnerability Details

File Location: photo-protocol.md:5-7
Vulnerability Type: Conflicting sensitive-image collection controls
Risk Level: Medium

Complete Code Snippet:

markdown
- Ask whether photo tracking is actually useful for this case.
- Confirm the user is comfortable storing photo metadata locally.
- Do not ask for intimate-area or minor photos unless a lawful caregiver context is already clear and the user explicitly wants tracking.

This exception conflicts with categorical restrictions elsewhere in the Skill:

markdown
- ask for or store intimate-area images or any photos of minors

and:

markdown
- Do not request or store photos of minors.
- If those contexts appear, stop image collection and direct the user to in-person or secure clinician workflows rather than local tracking.

Technical Analysis

photo-protocol.md:7 permits the Agent to request or track a minor's photograph when a user claims a lawful caregiver context and explicitly requests tracking. That instruction directly conflicts with the unconditional prohibitions in SKILL.md:55-59, legal-boundaries.md:12-16, and memory-template.md:106-113.

Because the Skill directs the Agent to consult photo-protocol.md when photos are involved, the more specific protocol can be interpreted as an authorized exception to the global policy. No mechanism verifies caregiver authority, the subject's age, consent, or whether the image is non-intimate. This control inconsistency can therefore result in processing sensitive medical imagery that the Skill claims it will never request or store.

Attack Path

  1. A user states that they are the lawful caregiver of a minor.
  2. The user asks the Agent to establish photo tracking for the minor's skin concern.
  3. The Agent loads the photo protocol and applies the exception at photo-protocol.md:7.
  4. The Agent requests a photograph or records its file/source ...[truncated 677 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the caregiver exception and replace line 7 with an unconditional control:

    markdown
    - Never request, receive, store, or track photographs of minors or intimate areas. Redirect the user to an approved secure clinician workflow.
    
  2. Align photo-protocol.md, SKILL.md, legal-boundaries.md, memory-template.md, and setup.md so all files enforce the same rule.

  3. Clarify that caregiver context may support text-only triage but must never enable image collection or image-metadata storage.

  4. Require the Agent to stop the photo workflow and avoid creating a photo log whenever the subject is identified as a minor.

  5. Add a pre-storage validation step that checks adult status, non-intimate body location, and explicit storage approval before creating photo-related records.

  6. Add tests covering conflicting requests, including caregiver claims, unclear age, and mixed adult/minor cases, to ensure the strict prohibition always prevails.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template is designed to store highly sensitive health information, including diagnoses, treatment history, body-site details, and photo logs, but it does not include a prominent user-facing warning about privacy risks, retention, or the consequences of storing intimate medical data. In the dermatology context, this is more dangerous because photos and lesion histories may reveal protected health information and highly personal details, especially when tracked over time.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template explicitly includes an 'Use automatically when' activation mechanism but leaves the triggering conditions undefined. In a health-related skill handling sensitive dermatology data, vague auto-activation can cause the agent to begin using or updating memory in situations the user did not clearly consent to, increasing the risk of over-collection and privacy violations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup explicitly offers automatic activation whenever the user mentions broad, common topics like skin issues, rashes, moles, lesions, or dermatologist visits. This can cause the skill to engage on incidental mentions and begin collecting sensitive health context earlier than the user intended, increasing privacy and consent risk in a medical domain.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.md (reported line 22)May include surrounding context.

bash
mkdir -p ~/dermatologist/cases ~/dermatologist/exports ~/dermatologist/archive
touch ~/dermatologist/memory.md
chmod 700 ~/dermatologist
  1. If approved and memory.md is empty, initialize it from memory-template.md.
  2. Ask what matters most right now:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The example preference 'Use dermatologist automatically when I mention skin tracking or dermatologist visits' prescribes automatic behavior tied to language cues rather than preserving explicit user choice at runtime. This is a natural-language policy concern because it encourages a fixed invocation mode without emphasizing ongoing opt-in or confirmation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.