Back to skill

Security audit

Clinical Doc Assistant

Security checks for vulnerabilities and agentic risk

Overview

This healthcare documentation skill is mostly purpose-aligned, but it handles patient data and includes an unsafe hosted-backend scaffold that needs careful review before real use.

Use this only with synthetic sandbox data unless you have verified compliant infrastructure and BAAs for every service that can receive PHI. Do not deploy backend.py as-is: replace the test-key authentication, persist credit accounting, restrict CORS, add rate limits, minimize/redact patient data before LLM calls, and require clinician review before any generated text is used.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
backend.py:63
Finding

Hard-Coded Shared Test API Key Bypasses Account Authentication

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
backend.py:160
Finding

Untrusted Clinical Data Is Directly Interpolated into LLM Instructions

Content
View full analysis
str: """Build a structured prompt for the LLM based on document type.""" patient = req.patient_context doc_type = req.document_type notes = req.additional_notes or "" base = f"""You are a clinical documentation assistant. Generate a professional {doc_type.replace("_", " ")} draft. Patient context: {_format_patient_context(patient)} Additional notes from clinician: {notes} Instructions: - Use standard clinical terminology and formatting - Flag any missing data with [MISSING: field name] placeholders - This is a DRAFT for clinician review — clearly state this at the top - Do NOT make diagnostic recommendations beyond what is supported by the provided data """ if doc_type == "soap_note": base += "\nFormat as: SUBJECTIVE / OBJECTIVE / ASSESSMENT / PLAN" elif doc_type == "referral": base += f"\nFormat as a professional referral letter. Referring to: {req.specialty or '[Specialist]'}" elif doc_type == "prior_auth": base += "\nFormat as a prior authorization clinical justification narrative." elif doc_type == "discharge": base += "\nFormat as a complete discharge summary with: Admission Dx, Hospital Course, Discharge Dx, Discharge Meds, Follow-up Plan." elif doc_type == "avs": base += "\nFormat in plain English at an 8th-grade reading level for the patient." return base def _format_patient_context(patient: dict) -> str: lines = [] for key, value in patient.items(): if value: lines.append(f" {key}: {value}") return "\n".join(lines) if lines else " No structured data provided." ``` ### Technical Analysis The backend concatenates `document_type`, `patient_context`, `additional_notes`, and `s ...[truncated 2722 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · README.md (reported line 31)May include surrounding context.

clawhub login

text

### 3. Update SKILL.md author field
Edit `SKILL.md` and replace `your-clawhub-handle` with your actual handle.

### 4. Publish

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior materially diverges from the declared purpose: it references a hosted credit-based backend, external Anthropic transmission, and monetization/checkout behavior while apparently not implementing the claimed FHIR retrieval features. In a PHI-handling skill, this mismatch prevents informed consent, obscures where patient data actually goes, and can cause operators to trust nonexistent safeguards or integrations.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The prompt is constructed by embedding patient-provided structured context and free-text notes verbatim, which can include direct identifiers, diagnoses, medications, and other PHI. Because that prompt is then sent to an external LLM, this creates a straightforward sensitive-data exposure path, made more serious by the healthcare context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file describes authentication with FHIR_CLIENT_SECRET, token exchange, and authorized FHIR requests, all of which involve sensitive credentials and access to protected health data. Under the markdown-file warning criterion, the documentation should clearly disclose privacy and system-impact implications of sending patient data and secrets to external services.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares environment-variable and network-dependent behavior but provides no explicit tool-scope or permission boundaries. In a healthcare context, undeclared network/env access is dangerous because the agent may access secrets and transmit patient data to external services without clear user-visible authorization controls.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

Although the manifest says the skill is for documentation only and not diagnosis or prescribing, the example SOAP output includes assessment and plan content that can function as clinical recommendations. In clinical workflows, this can overstep the stated safety boundary and encourage reliance on generated medical judgment, creating patient-safety and liability risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill explicitly supports sending requests to an external hosted backend, and elsewhere states that patient context may be transmitted for generation. In a healthcare setting, external transmission of clinical context creates significant PHI exposure risk if the endpoint, retention, encryption, access controls, and BAA status are not strictly controlled and transparently enforced.

Content

Scanner excerpt · SKILL.md (reported line 315)May include surrounding context.

Set these variables to enable:

bash
export CLINICAL_DOC_API_URL="https://api.yourdomain.com/v1"
export CLINICAL_DOC_API_KEY="your-api-key"

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill for drafting and retrieving clinical documentation via FHIR/manual input, with explicit documentation-only scope. This backend also exposes account usage tracking and Stripe-based credit purchasing endpoints, which are product monetization features not described as part of the skill's behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code sends structured patient context to an external LLM provider, but the skill description does not clearly disclose that protected health information may leave the system boundary. In a healthcare documentation context, undisclosed third-party transmission of patient data materially increases privacy, compliance, and trust risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The comment asserts that no PHI is stored after the LLM call, but the code does not enforce deletion, prevent downstream logging, or verify retention behavior by dependencies and providers. In a clinical setting, unsupported privacy guarantees can mislead operators into handling PHI less cautiously than required.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Patient context is transmitted over the network to an external LLM service without any evident user-facing warning or consent step in this backend flow. Because the skill handles clinical documentation, this creates significant confidentiality and regulatory risk if users assume processing stays within their EHR or local environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The AVS branch instructs the model to format output "in plain English," which imposes a specific language choice. Under the policy, language constraints should not be forced without user opt-in or a clearly documented, justified locale limitation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The external call to api.anthropic.com is itself expected functionality, but in this application it represents outbound transmission of clinical content to a third party. The danger arises from the combination of healthcare data, insufficient disclosure, and lack of visible minimization or consent controls rather than the mere existence of an HTTP request.

Content

Scanner excerpt · backend.py (reported line 209)May include surrounding context.

python
async with httpx.AsyncClient() as client:
        response = await client.post(
            "https://api.anthropic.com/v1/messages",
            headers={
                "x-api-key": api_key,
                "anthropic-version": "2023-06-01",

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes pulling structured patient data from FHIR and generating documentation drafts. The prior authorization section adds a separate capability: 'looks up the requested item's typical HCPCS/CPT code,' which is not described in the manifest and is not a direct FHIR retrieval behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.