Back to skill

Security audit

Redacta

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly purpose-aligned, but it handles sensitive medical text with review-worthy risks including a predictable temp file and an unpinned MCP install path.

Review before installing in clinical or regulated settings. Prefer stdin or a secure per-run temp file with immediate deletion instead of /tmp/redacta_input.txt, keep token maps separate and protected, and pin any MCP npm invocation to an exact reviewed version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:35
Finding

Predictable Temporary File Stores Unredacted Medical Data

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
mcp-server/README.md:30
Finding

Unpinned MCP Package Is Automatically Downloaded and Executed

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (46)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code does implement part of the declared purpose: deterministic pseudonymisation of structured identifiers, token-map-based re-identification, and reporting. However, the description claims a broader capability set than this code chunk actually provides. The code explicitly limits itself to deterministic structured identifiers and says names, addresses, and identifying ages are out of scope for this library. That is a material mismatch because those contextual redaction capabilities are presented in the description as part of the skill’s behavior. The description also mentions stricter HIPAA Safe Harbor handling, but no such mode or logic appears in this code chunk. There is no evidence of unrelated or risky undeclared behavior; the issue is overclaiming substantive capabilities beyond what the code shown does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The supplied code is consistent with part of the description: it locally pseudonymises several structured identifiers and returns redacted text, a report, and a token map. However, the declared description presents a broader end-user capability than this code actually provides. The code explicitly states it is 'Layer 1' only and that contextual identifiers are handled separately by an agent, meaning names, full addresses, and identifying ages are not implemented here. It also lacks any function to reverse redaction from the token map, despite the description claiming re-identification capability. Likewise, there is no stricter HIPAA Safe Harbor mode that removes all dates, ages, and remaining HIPAA identifiers; in fact, dates are only redacted when explicitly adjacent to DOB keywords, which is narrower than Safe Harbor. Additionally, while the description focuses on UK clinical identifiers, the code also includes undeclared SSN and US ZIP handling, though those are still related de-identification features rather than a different primary purpose. Overall, the code is a narrower structured redaction component, not the full capability set described.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: fast-uri==3.1.2 — 6 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +3 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

fast-uri 3.1.2 has multiple high-severity URI parsing advisories including host confusion and SSRF-adjacent issues. This lockfile alone does not show direct attacker-controlled URL fetching, but because it is a runtime dependency under schema/validation tooling, retaining a parser with known canonicalization flaws is a real risk if any URL validation or allowlisting relies on it.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.2.0 — 3 advisory(ies): CVE-2026-54272 (ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSR); CVE-2026-69198 (ip-address: a CIDR suffix on the parsed address suppresses special-use classific); CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco)

High
Category
Supply Chain
Confidence
80% confidence
Finding

ip-address 10.2.0 has advisories around misclassification and parsing inconsistencies that can undermine SSRF protections or network allow/deny logic. The current skill's purpose is document redaction, not network mediation, which reduces contextual danger, but if the MCP stack uses IP-based trust, rate limiting, or proxy logic, these flaws can still matter.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: nanoid==3.3.12 — 2 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-67213 (nanoid: custom generators can loop indefinitely when size is zero)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: nanoid==3.3.12 — 2 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-67213 (nanoid: custom generators can loop indefinitely when size is zero)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: postcss==8.5.15 — 2 advisory(ies): CVE-2026-69153 (PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappi); CVE-2026-73646 (PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) l)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: postcss==8.5.15 — 2 advisory(ies): CVE-2026-69153 (PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappi); CVE-2026-73646 (PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) l)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README says the skill may trigger automatically when the user asks to "redact or de-identify clinical text," but it does not define precise trigger phrases, scope limits, or exclusion conditions. This is broad natural-language activation guidance for a markdown file and could cause unintended invocation for general redaction-related requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs writing sensitive medical text verbatim to a temporary file before processing, but does not provide strong safeguards around file permissions, secure deletion, retention, or user warning about local persistence. In a clinical context, this can leave regulated PHI/PII exposed on disk, in temp directories, backups, crash dumps, or to other local users/processes, undermining the privacy goal of the tool.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger examples are broad natural-language phrases that could plausibly appear in ordinary conversation, making accidental tool invocation more likely in MCP-capable clients. In this skill's context, unintended invocation is more sensitive because the tool handles medical text and can produce a reversible token_map, so accidental processing could expose or mishandle PHI if client-side confirmations or scoping are weak.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to run the MCP server via npx redacta-mcp without pinning a specific version or integrity-verified source. That creates a supply-chain risk: users may unknowingly execute a newly published or compromised package version, and because this tool processes sensitive clinical data locally, a malicious update could exfiltrate PHI/PII or alter redaction behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README narrows the package’s capabilities to deterministic and keyword-anchored detection and explicitly says free-text name reasoning is provided by a different skill, while the skill metadata claims contextual reasoning for patient names, addresses, and identifying ages. In a medical de-identification context, this mismatch can cause users to overtrust the protection level and send insufficiently redacted PHI to downstream AI tools or third parties.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes pseudonymising medical and clinical documents by replacing patient identifiers such as NHS numbers, NI numbers, DOBs, postcodes, phone numbers, emails, hospital/MRN numbers, names, addresses, and HIPAA identifiers. This file additionally detects and tokenises payment card numbers, IBANs, account/member/policy numbers, URLs, IP addresses, and vehicle registrations, which are broader general-purpose PII/financial-data capabilities not justified by the stated clinical redaction purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Lines L525-L530 document a function that would 're-scan already-redacted text' and return leftover-identifier findings. However, the exported function beginning at L539 is reinstate(), which instead restores original values from a token map. This is an active contradiction in inline documentation, not just an omission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The reinstate function restores original sensitive values from the token map back into text, which is a privacy-sensitive and potentially irreversible disclosure step. While comments describe what the function does, there is no confirmation prompt or explicit user-facing warning/log at the point of this operation to disclose that redacted identifiers will be reinserted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code restores original sensitive values from a token map and emits the re-identified text to stdout/JSON output. Although the module docstring explains the purpose, there is no runtime confirmation, warning, or user-facing disclosure near the operation itself that the tool will output restored real data, which could expose personal data if piped or logged inadvertently.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script’s default JSON output includes token_map, which directly maps redaction tokens back to original identifiers such as NHS numbers, emails, phone numbers, and DOBs. In a medical redaction skill, this undermines the safety goal of pseudonymisation because downstream logs, terminal history, copied output, or secondary systems may receive the sensitive values even when the caller expected only redacted text.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE (reported line 12)May include surrounding context.

text
the Software, and to permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN
AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a medical-document pseudonymisation tool focused on patient identifiers such as names, NHS numbers, dates of birth, addresses, and similar clinical de-identification targets. The README expands actual detection behavior to also cover general PII like URLs, IP addresses, payment cards, IBANs, account numbers, and vehicle registrations, which goes beyond the manifest's stated scope.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @hono/node-server==1.19.14 — 1 advisory(ies): GHSA-frvp-7c67-39w9 (Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encode)

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The lockfile pins @hono/node-server 1.19.14, and the cited advisory is a real dependency risk if this package's static file serving is used on Windows. In this skill, the package is pulled transitively by the MCP SDK and the file alone does not prove vulnerable code paths are exposed, but keeping a known vulnerable runtime dependency is still a genuine supply-chain issue.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: body-parser==2.2.2 — 1 advisory(ies): CVE-2026-12590 (body-parser vulnerable to denial of service when invalid limit value silently di)

Low
Category
Supply Chain
Confidence
80% confidence
Finding

body-parser 2.2.2 is a runtime dependency through Express, and the cited issue can lead to denial of service when malformed limit handling is triggered. For an MCP server that may process untrusted requests or large clinical documents, even low-severity parser DoS is relevant because availability matters in healthcare workflows.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: hono==4.12.25 — 10 advisory(ies): CVE-2026-71848 (Hono: Algorithmic Complexity DoS in Language Middleware); CVE-2026-71849 (Hono: Proxy Helper does not remove response headers listed in the `Connection` h); CVE-2026-69207 (Hono: ReDoS in CORS middleware via Access-Control-Request-Headers) +7 more

Low
Category
Supply Chain
Confidence
77% confidence
Finding

hono 4.12.25 carries multiple advisories affecting middleware and helper behavior. Since this package is brought in by the MCP SDK and the provided skill is a text-redaction service rather than a general web app, exploitability depends on whether the affected Hono features are actually enabled, but the presence of known vulnerable runtime web framework code is still a valid dependency vulnerability.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: qs==6.15.2 — 2 advisory(ies): CVE-2026-82417 (qs: Denial of Service via Attacker Controlled isBuffer); CVE-2026-82562 (qs array-limit bypass via bracket-key comma parsing)

Low
Category
Supply Chain
Confidence
79% confidence
Finding

qs is a runtime dependency used by Express/body-parser for query string parsing, and the listed issues can cause denial of service or parser limit bypass under malicious inputs. Even though the service is focused on redacting medical text rather than complex query handling, publicly reachable request parsing bugs still create a real availability risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The package description at L04 makes an absolute behavioral claim: 'runs locally, nothing leaves your machine.' In this file, the actual implementation is not shown; only dependencies on external packages and an MCP server runtime are declared, so the documentation asserts a stronger guarantee than this code artifact itself demonstrates.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.