Back to skill

Security audit

Mediwise Health Suite

Security checks for vulnerabilities and agentic risk

Overview

This health-management skill is broadly coherent, but it needs Review because it handles sensitive health data and has confirmed access-control, persistence, credential, network, and backup-restore safety gaps.

Install only after reviewing the multi-user and external-provider risks. Use it as a single-user local tool unless owner_id is enforced by trusted platform identity, avoid custom remote HTTP model endpoints, do not put passwords or API keys in chat, protect config and backup files as sensitive medical records, and avoid restoring backups from untrusted sources.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (6)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
mediwise-health-tracker/index.js:466
Finding

Missing Fail-Closed Tenant Isolation in the Skill Entry Point

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
mediwise-health-tracker/SKILL.md:231
Finding

Unconsented Persistence of Incidental Health Statements and Model-Generated Inferences

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
mediwise-health-tracker/scripts/config.py:178
Finding

Plaintext Secret Storage Without Enforced File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
mediwise-health-tracker/scripts/setup.py:882
Finding

Absolute-Path File Overwrite During Backup Restoration

Content
View full analysis
`. 4. The `startswith("..")` check accepts the absolute member name. 5. `os.path.join` resolves the destination outside `DATA_DIR`. 6. The restoration process overwrites the attacker-selected file with archive-controlled content. 7. If the overwritten file is loade ...[truncated 617 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
mediwise-health-tracker/scripts/smart_intake.py:113
Finding

Custom LLM Endpoints Can Receive API Credentials and Medical Data Over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
wearable-sync/SKILL.md:23
Finding

Unpinned Garmin Authentication Dependency

Content
View full analysis
Garmin 使用非官方 API(模拟 Web 登录),无需申请开发者账号。需要用户的 Garmin Connect 账号和密码。 ``` The root dependency file also leaves the package unpinned at `requirements.txt:10-11`: ```text # Garmin Connect provider (wearable-sync) # garminconnect>=0.2.0 # pip install garminconnect ``` ### Technical Analysis The installation instructions retrieve the latest available `garminconnect` package from the active Python package index without a reviewed version pin or integrity hash. This dependency operates in a particularly sensitive path: it receives Garmin account credentials, creates or loads OAuth tokens, communicates with Garmin's service, and processes detailed health and activity data. A compromised or unexpectedly changed upstream release would execute with the privileges of the Agent's operating-system account. The lower-bound example in `requirements.txt` does not provide reproducibility because it allows all future versions, and it is commented out rather than forming an enforceable locked dependency declaration. ### Attack Path 1. A user follows the Skill instruction and runs `pip install garminconnect`. 2. The package resolver selects the newest release available from the configured package index. 3. The selected release is compromised, malicious, or resolves from an untrusted mirror. 4. The package executes during Garmin authentication or synchronization. 5. Malicious dependency code accesses the Garmin password, stored tokens, synchronized health data, local databases, and other files available to the Agent user. 6. The dependency can transmit those assets or modify local application state. ### Impact Assessment A compromised dependency could obtain: - Garmin account credentials during ...[truncated 356 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (351)

Tainted flow: 'req' from os.environ.get (line 251, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · diet-tracker/scripts/food_lookup.py (reported line 252)May include surrounding context.

python
)
    try:
        req = urllib.request.Request(url, headers={'User-Agent': 'mediwise-health/1.0'})
        with urllib.request.urlopen(req, timeout=8) as resp:
            data = json.loads(resp.read())
    except Exception as e:
        return [{'error': f'USDA API 请求失败: {e}'}]

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section encourages users to submit lab report images to an externally configured vision provider but does not warn that highly sensitive medical data may leave the local environment and be processed by a third party. In a health-management skill, omission of this notice is dangerous because users may assume local-only handling and unknowingly disclose protected personal health information.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The English image-recognition section repeats the same risky omission: users are told how to send medical documents to an external model endpoint but are not warned about third-party processing of health information. Because the skill handles medical records, missing disclosure materially increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example dialogue models a workflow where the assistant asks for and accepts Garmin credentials directly in plain chat. This is a serious anti-pattern because chat systems commonly log messages, expose them to operators, plugins, backups, or other integrations, turning a convenience feature into a credential collection channel for a third-party account tied to sensitive health data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The finding highlights undeclared sleep tracking and the use of owner/member identifiers, along with a warning that missing owner_id leads to access to all local data in single-user mode. In a shared or agent-mediated deployment, that behavior can accidentally collapse tenant boundaries and expose one person's medical data to another.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

md
也可以用 `setup.py` 命令配置(保存到 `config.json`,环境变量优先级更高):

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

When owner_id is omitted, the skill explicitly enters a mode where all local data is accessible, bypassing tenant/user scoping. In a family health suite handling sensitive health and diet records, this can expose or modify another person's data simply by omitting an identifier, which is especially risky because the behavior is intentional and only logged as a warning.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script accepts --owner-id and imports verify_member_ownership, but none of the command handlers enforce that the caller owns or is authorized to access the supplied member_id. As a result, any caller who can invoke the script can set, view, or summarize nutrition goals and intake for arbitrary members, exposing sensitive health data and enabling unauthorized modification.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The setup instructions tell users to place an API key in a local .env file, which introduces credential-handling risk if the file is later committed, copied, or exposed through backups or misconfigured permissions. In the context of a health-management skill that may already store sensitive data, weak secret-handling practices raise the blast radius of compromise.

Content

Scanner excerpt · docs/AGENT_SETUP.md (reported line 219)May include surrounding context.

bash
cd ~/.openclaw/workspace-health/skills/mediwise-health-suite
cp .env.example .env
# 编辑 .env,填入视觉模型 API Key

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/INSTALLATION.md (reported line 59)May include surrounding context.

md
**图片/PDF 识别(化验单、体检报告等)需要配置外部视觉模型**,否则图片类功能无法使用。

**推荐方式:通过环境变量配置(支持 .env 文件)**

复制模板文件并填入你的 API Key:

Static analysis

No suspicious patterns detected.