Back to skill

Security audit

Doctor

Security checks across malware telemetry and agentic risk

Overview

This medical helper is openly local and non-executable, but it automatically reads and changes sensitive health and related personal records with too little user control.

Install only if you want this skill to maintain a local longitudinal medical record. Before using it, set health_logging to minimal or off if you do not want automatic storage, and review the declared folders because the skill can update health notes, appointments, contacts, projects, and a health-insurance subscription file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (50)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to read and update several persistent files outside narrow medical triage, including shared bookings, contacts, episodes, health profile, and finance records. This creates overbroad authority and enables unintended cross-domain data modification, which is especially risky because the Doctor skill handles highly sensitive health information and could silently persist or alter records beyond the user’s immediate request.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The file expands the medical skill into financial recordkeeping by directing storage and maintenance of insurance premiums, plan details, and subscription data. Mixing medical and financial data handling increases privacy exposure, broadens the blast radius of mistakes or abuse, and exceeds the stated medical scope, making unauthorized persistence of sensitive financial metadata more likely.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The skill instructs reading a dependent child's health file from shared storage before answering, pulling in sensitive data beyond the immediate user prompt. This creates unnecessary cross-skill data access and expands exposure of pediatric medical information, increasing the chance of privacy violations, over-collection, and use of stale or unrelated data in clinical guidance.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The file directs the model to create and update multiple shared records, indexes, and contact files in the same turn, far beyond symptom triage. That broad write behavior increases the blast radius of any mistake, enables uncontrolled propagation of a child's health data across the system, and can expose sensitive information to unrelated skills or future sessions.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs persistent writes to local health-profile, memory, and artifact files, including creating, updating, and deleting entries. In a medical context this expands the skill from advisory/triage into health-record management without explicit user authorization, increasing the risk of unintended retention, privacy violations, and propagation of incorrect medical data into future decisions.

Description-Behavior Mismatch

Low
Confidence
88% confidence
Finding
The instruction to always read longitudinal profile, metric, and memory files before answering creates a broad, automatic access pattern to sensitive medical history beyond what is necessary for many one-off questions. This increases exposure of personal health data and can cause the skill to rely on stale or unrelated records when responding.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The file directs the agent to read sensitive health records and an emergency summary before giving emergency guidance, which exceeds the stated triage function and creates unnecessary access to personal medical data. In an emergency-oriented skill, broad file reads increase the chance of privacy leakage, overcollection, and use of stale or incorrect data during a high-risk interaction.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
This content provides detailed first-aid operational instructions even though the skill metadata says step-by-step first-aid drills belong to a different skill. Scope drift is dangerous in a medical context because users may rely on unsupported emergency treatment instructions from a triage tool, increasing the risk of harmful or jurisdictionally incorrect advice.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The document instructs the agent to write post-incident details, allergies, medication artifacts, and summaries into multiple persistent files after an emergency. That is unnecessary for immediate triage and creates a serious integrity and privacy risk by modifying sensitive health records during or after a stressful event without strong confirmation or validation.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The instruction to pull emergency contact information from a contacts file is not justified by the triage-only purpose and expands access into unrelated personal data. In a medical skill, this broadens the blast radius from health guidance to social-graph exposure, enabling unnecessary disclosure of names and contact details.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs reading a persistent local health profile before giving advice, which expands behavior from transient triage into accessing stored sensitive medical data. Even if clinically relevant, this creates privacy and scope-risk because the user is not told that local records will be accessed, and such access could expose or over-collect unrelated health information.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The file directs the skill to write medical episode records, rehabilitation artifacts, and vaccine updates into persistent local storage in the same turn. This goes beyond advisory triage and creates a significant integrity and privacy risk because the skill may silently create or modify longitudinal medical records without explicit confirmation, increasing the chance of unauthorized retention or incorrect health data being recorded.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill instructs the agent to persist detailed health measurements, repeat dates, and written interpretations into long-lived local files. That expands the skill from transient triage/explanation into retention of sensitive medical data, increasing privacy risk, unintended secondary use, and exposure if other skills or users can access the same storage.

Context-Inappropriate Capability

Low
Confidence
80% confidence
Finding
The file tells the agent to read a broad health profile and indexed metric histories before interpreting a result. Even if medically useful, this grants access to more longitudinal sensitive data than is strictly required for many single-result explanations, creating unnecessary data exposure and scope creep beyond the core task.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The file instructs the agent to write persistent updates to `~/Clawic/data/health/profile.md` and create care-plan artifacts in the same turn. That exceeds symptom triage and medication guidance into durable medical-record management, which can silently alter sensitive health data, create incorrect longitudinal records, and influence future medical advice if the stored data is wrong or stale.

Context-Inappropriate Capability

Low
Confidence
84% confidence
Finding
The skill treats pregnancy status and restrictions in `config.yaml` as operational state and instructs the agent to note and re-check that status on future turns. Even though the safety motivation is legitimate, this is still persistence and reuse of highly sensitive reproductive-health data beyond the manifest's stated advisory role, creating privacy and correctness risks if the state is stored or inferred inaccurately.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill goes beyond medical triage and instructs persistent creation and modification of health, episode, due-date, and artifact records. That expands authority from advice into ongoing record management of sensitive medical data, increasing the chance of unauthorized retention, incorrect records, and privacy harm if the user did not explicitly request those writes.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The file directs the agent to add and edit contact records for relatives, which is not necessary for immediate symptom triage and broadens access to third-party personal data. This creates a risk of storing or changing information about other people without clear authorization, especially in a medical context where family relationships and health status are highly sensitive.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The skill directs the agent to write trip details into a shared bookings file even though the stated Doctor skill purpose is prevention, screening, vaccines, and travel health advice. This expands scope from medical guidance into itinerary record management, creating unnecessary collection and persistence of personal travel metadata that could be misused or exposed.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The file directs the agent to write sensitive reproductive-health information, screening data, and due dates into persistent profile and artifact files 'in the same turn' without any indication of user authorization or confirmation. In a medical context this creates a real privacy and integrity risk: the agent may store highly sensitive data or alter longitudinal records unexpectedly, which can affect future medical advice and expose intimate health information.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
This line grants an unjustified ability to modify persistent health profile, measurement, screening, and scheduling data from a document whose primary purpose is clinical guidance. Because these records gate future drug and risk answers, unauthorized or mistaken updates can propagate into later decisions, producing privacy harm and potentially unsafe medical recommendations.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to persist episode histories and update allergy/profile records, which expands behavior from triage into long-term medical record management. In a health context, this creates significant privacy and integrity risk because sensitive data may be stored or altered without explicit user consent, confirmation, or limits on what should be retained.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The file directs the agent to read persistent health profile and episode-log data before symptom matching, broadening access beyond the immediate user request. Even if clinically useful, this is a privacy-expanding behavior that can expose unrelated historical medical information and create unnecessary data dependence for routine triage.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill goes beyond one-turn triage by instructing the agent to persistently write symptoms, urgency decisions, tripwires, and follow-up outcomes into health record and artifact files. In a medical context, this creates unnecessary retention of highly sensitive data and expands the blast radius if the agent writes incorrect, excessive, or privacy-sensitive information without explicit user consent.

Context-Inappropriate Capability

Low
Confidence
81% confidence
Finding
The skill requires reading broad medical profile and memory files before triage, including conditions, medicines, allergies, pregnancy status, and prior episode logs. While some context can improve safety, making broad file access a default prerequisite risks over-collection and use of unrelated sensitive data beyond what is strictly needed for the current symptom assessment.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.