Back to skill

Security audit

Health Industry Specialist

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned for beauty and weight-loss business operations, but it should go to Review because it handles sensitive customer data, messaging, and third-party sync without enough consent and safety boundaries.

Before installing, treat this as a Review item for any real customer workflow. Use it only with documented customer consent, clear opt-in and opt-out for messages, written permission for photos or marketing claims, scoped third-party sharing, and human confirmation before changing records or appointments. Do not rely on it for medical, postpartum, metabolic, or personalized weight-loss advice without qualified professional review.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation examples are broad enough that a user could trigger customer-management operations without clear confirmation boundaries, especially around CRM-related actions like record access or updates. In a skill that references customer management and scheduling, ambiguous activation increases the risk of unintended data handling or unauthorized operational actions.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill prominently advertises customer management and intelligent appointment capabilities but does not place strong privacy, consent, or operational safety warnings in the main usage description. Because this skill appears intended for handling customer data in a health-related business context, weak upfront guidance can lead to inappropriate collection, disclosure, or modification of sensitive personal information.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The marketing section explicitly promotes before/after customer results, private-message consultation, store booking, and customer privacy, but it does not include any guidance on informed consent, image/use authorization, lawful collection of health or body data, or secure handling of personal information. In a beauty services context, this can lead to improper collection, sharing, or promotional use of sensitive personal and quasi-health data, increasing privacy and compliance risk.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The template collects contact details and health-related information, which are sensitive personal data categories, but the collection fields are presented without any embedded notice about consent, lawful basis, retention, access controls, or disclosure limitations. In a CRM context for health/wellness services, this omission can lead to unlawful over-collection, improper handling, and privacy violations if operators adopt the template as-is.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The reminder and follow-up workflows describe automated outbound messaging using customer data, but they do not include any opt-in, notice, frequency controls, or unsubscribe/opt-out handling. This creates a realistic risk of unauthorized automated contact, privacy complaints, and regulatory noncompliance, especially where health or service-status information may be inferred from the messages.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The integration section instructs syncing customer data with external platforms such as Douyin and WeChat without addressing third-party sharing disclosures, processor/vendor controls, cross-system permissions, or data minimization. This is dangerous because sensitive customer and health-related information could be propagated to external services beyond customer expectations, increasing exposure and compliance risk.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The document gives individualized diet and exercise guidance, including calorie deficits, meal frequency, exercise frequency, and references to medical scenarios such as postpartum recovery and metabolic issues, but it does not clearly warn users to consult qualified medical professionals before applying these recommendations. In a weight-loss context, users with conditions such as diabetes, hypertension, eating disorders, pregnancy/postpartum status, or medication use could be harmed by following generalized advice without clinical screening.

Static analysis

No suspicious patterns detected.