T05 · Unauthorized Access and Privilege Escalation
- Location
mediwise-health-tracker/index.js:466- Finding
Missing Fail-Closed Tenant Isolation in the Skill Entry Point
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This health-management skill is broadly coherent, but it needs Review because it handles sensitive health data and has confirmed access-control, persistence, credential, network, and backup-restore safety gaps.
Install only after reviewing the multi-user and external-provider risks. Use it as a single-user local tool unless owner_id is enforced by trusted platform identity, avoid custom remote HTTP model endpoints, do not put passwords or API keys in chat, protect config and backup files as sensitive medical records, and avoid restoring backups from untrusted sources.
mediwise-health-tracker/index.js:466Missing Fail-Closed Tenant Isolation in the Skill Entry Point
mediwise-health-tracker/SKILL.md:231Unconsented Persistence of Incidental Health Statements and Model-Generated Inferences
mediwise-health-tracker/scripts/config.py:178Plaintext Secret Storage Without Enforced File Permissions
mediwise-health-tracker/scripts/setup.py:882Absolute-Path File Overwrite During Backup Restoration
mediwise-health-tracker/scripts/smart_intake.py:113Custom LLM Endpoints Can Receive API Credentials and Medical Data Over Plaintext HTTP
wearable-sync/SKILL.md:23Unpinned Garmin Authentication Dependency
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
)
try:
req = urllib.request.Request(url, headers={'User-Agent': 'mediwise-health/1.0'})
with urllib.request.urlopen(req, timeout=8) as resp:
data = json.loads(resp.read())
except Exception as e:
return [{'error': f'USDA API 请求失败: {e}'}]
This section encourages users to submit lab report images to an externally configured vision provider but does not warn that highly sensitive medical data may leave the local environment and be processed by a third party. In a health-management skill, omission of this notice is dangerous because users may assume local-only handling and unknowingly disclose protected personal health information.
The English image-recognition section repeats the same risky omission: users are told how to send medical documents to an external model endpoint but are not warned about third-party processing of health information. Because the skill handles medical records, missing disclosure materially increases privacy and compliance risk.
The example dialogue models a workflow where the assistant asks for and accepts Garmin credentials directly in plain chat. This is a serious anti-pattern because chat systems commonly log messages, expose them to operators, plugins, backups, or other integrations, turning a convenience feature into a credential collection channel for a third-party account tied to sensitive health data.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.
Referenced artifact was not completely inspected
也可以用 `setup.py` 命令配置(保存到 `config.json`,环境变量优先级更高):
When owner_id is omitted, the skill explicitly enters a mode where all local data is accessible, bypassing tenant/user scoping. In a family health suite handling sensitive health and diet records, this can expose or modify another person's data simply by omitting an identifier, which is especially risky because the behavior is intentional and only logged as a warning.
The script accepts --owner-id and imports verify_member_ownership, but none of the command handlers enforce that the caller owns or is authorized to access the supplied member_id. As a result, any caller who can invoke the script can set, view, or summarize nutrition goals and intake for arbitrary members, exposing sensitive health data and enabling unauthorized modification.
The setup instructions tell users to place an API key in a local .env file, which introduces credential-handling risk if the file is later committed, copied, or exposed through backups or misconfigured permissions. In the context of a health-management skill that may already store sensitive data, weak secret-handling practices raise the blast radius of compromise.
cd ~/.openclaw/workspace-health/skills/mediwise-health-suite
cp .env.example .env
# 编辑 .env,填入视觉模型 API Key
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**图片/PDF 识别(化验单、体检报告等)需要配置外部视觉模型**,否则图片类功能无法使用。
**推荐方式:通过环境变量配置(支持 .env 文件)**
复制模板文件并填入你的 API Key:
No suspicious patterns detected.