Back to skill

Security audit

HIPAA Patient Comms

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for drafting patient communications, but it overstates what is safe for unsecured healthcare messages and requests unnecessary file-writing authority.

Review this skill before installing in a healthcare workflow. It can help remove obvious diagnosis, treatment, or medical-record details, but it should not be treated as a HIPAA compliance guarantee. Use it only with verified patient contact details, approved communication preferences, and your organization’s policy; avoid granting write_file unless there is a specific, scoped output need.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:17
Finding

Unnecessary Filesystem Capabilities Violate Least-Privilege Principles

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:17-20
Vulnerability Type: Excessive tool permissions
Risk Level: Medium

Vulnerable Configuration

yaml
tools:
  - read_file
  - write_file

Technical Analysis

The Skill is designed to draft and review patient-facing text, but it requests both read_file and write_file. No documented workflow in SKILL.md requires reading from or writing to the local filesystem.

In particular, write_file grants an integrity-affecting capability beyond the Skill's legitimate text-generation purpose. If untrusted patient-message content, imported text, or later prompt injection influences the agent, this unnecessary capability could be invoked to modify files accessible under the host's tool policy.

The precise filesystem privileges depend on runtime sandboxing and authorization controls; the configuration does not itself establish unrestricted filesystem access. Nevertheless, requesting an unused write capability unnecessarily increases the impact of agent manipulation.

Attack Path

  1. An operator supplies an untrusted message or document for HIPAA review.
  2. The content contains instructions intended to manipulate the agent into performing an unrelated file operation.
  3. Because the Skill declares write_file, the agent may attempt to follow those instructions using that capability.
  4. If runtime policy permits the target path, an accessible file may be created, overwritten, or poisoned.
  5. Modified configuration, documentation, or other agent-consumed data could subsequently affect project integrity or later sessions.

Impact Assessment

Successful exploitation could provide unauthorized modification of files within the runtime identity's writable scope. Possible consequences include loss of data integrity, corruption of project files, or poisoning of content later consumed by an agent or user.

This finding does not demonstrate operating- ...[truncated 158 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove both filesystem tools when the Skill only needs to return generated text:

    yaml
    tools: []
    
  • If file-based input is genuinely required, retain only read_file and restrict it to an explicitly approved workspace.

  • If output persistence is required, constrain write_file to a dedicated output directory.

  • Require explicit user confirmation before creating or overwriting a file.

  • Prohibit overwriting existing files by default and use collision-resistant output names.

  • Ensure the host runtime applies path canonicalization, blocks traversal, and denies access outside the approved directory.

  • Treat all patient-supplied or imported content as untrusted data rather than executable agent instructions.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:72
Finding

Healthcare-Linked Data Is Categorically Presented as Safe for Unsecured Communications

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:72-80
Additional Affected Locations: SKILL.md:88-119, SKILL.md:125-146
Vulnerability Type: Insecure handling of sensitive healthcare-related information
Risk Level: Medium

Vulnerable Guidance

markdown
### What IS Safe in General Communications
| Safe | Example |
|------|---------|
| First name only | "Hi Sarah" |
| Appointment date and time | "Tuesday March 25 at 2:00 PM" |
| Practice name and address | "Main Street Family Practice" |
| Generic purpose | "your upcoming appointment" (not "your cardiology appointment") |
| Office phone number | For the patient to call back |
| Patient portal link | "Log in to your patient portal for details" |
| Generic follow-up | "We'd love to see you for a visit" (not "time for your annual mammogram") |

The appointment template combines several of these data elements:

markdown
**Template — Email:**

Subject: Appointment Reminder — {{practice_name}}

Hi {{patient_first_name}},

This is a reminder that you have an appointment on {{appointment_date}} at {{appointment_time}} at {{practice_name}}.

Please arrive 15 minutes early. If you need to reschedule or cancel, call us at {{practice_phone}}.

See you soon! {{practice_name}}

text

The billing template additionally includes a balance:

markdown
Hi {{patient_first_name}},

Our records show a balance of {{balance_amount}} on your account with {{practice_name}}.

For details or to make a payment, please log in to your patient portal or call us at {{practice_phone}}.

Technical Analysis

The Skill labels first names, exact appointment dates and times, practice identity, portal references, and account balances as generally safe, then combines those fields in templates intended for email and SMS. Even without a diagnosis or treatment name, the combined message can reveal an identifiable person's relationshi ...[truncated 2146 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace categorical statements such as “safe” and “follow HIPAA safe-harbor guidelines” with context-sensitive language that does not guarantee compliance.
  • Require confirmation that the patient has authorized the selected communication channel and that the destination information has been verified.
  • Default to the least revealing message possible, especially for SMS and email previews.
  • Omit account balances and exact appointment details unless they are necessary, authorized, and permitted by organizational policy.
  • Use neutral callback language where practical, with sensitive details available only after authentication.
  • Validate portal links against an approved practice domain and avoid embedding patient-specific tokens in unsecured messages.
  • Add a pre-send checklist covering recipient verification, communication preferences, minimum-necessary review, and practice-specific policy.
  • Clearly state that the templates are drafting aids rather than legal or compliance guarantees, and direct organizations to their compliance officer for channel-specific requirements.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest trigger phrases include generic terms such as "patient email," "patient communication," "clinic email," and "healthcare communication." These are broad enough to overlap with many ordinary requests and the file does not provide exclusion conditions or negative examples in the trigger section, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.