T05 · Unauthorized Access and Privilege Escalation
- Location
backend.py:63- Finding
Hard-Coded Shared Test API Key Bypasses Account Authentication
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This healthcare documentation skill is mostly purpose-aligned, but it handles patient data and includes an unsafe hosted-backend scaffold that needs careful review before real use.
Use this only with synthetic sandbox data unless you have verified compliant infrastructure and BAAs for every service that can receive PHI. Do not deploy backend.py as-is: replace the test-key authentication, persist credit accounting, restrict CORS, add rate limits, minimize/redact patient data before LLM calls, and require clinician review before any generated text is used.
backend.py:63Hard-Coded Shared Test API Key Bypasses Account Authentication
backend.py:160Untrusted Clinical Data Is Directly Interpolated into LLM Instructions
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
clawhub login
### 3. Update SKILL.md author field
Edit `SKILL.md` and replace `your-clawhub-handle` with your actual handle.
### 4. Publish
The documented behavior materially diverges from the declared purpose: it references a hosted credit-based backend, external Anthropic transmission, and monetization/checkout behavior while apparently not implementing the claimed FHIR retrieval features. In a PHI-handling skill, this mismatch prevents informed consent, obscures where patient data actually goes, and can cause operators to trust nonexistent safeguards or integrations.
The prompt is constructed by embedding patient-provided structured context and free-text notes verbatim, which can include direct identifiers, diagnoses, medications, and other PHI. Because that prompt is then sent to an external LLM, this creates a straightforward sensitive-data exposure path, made more serious by the healthcare context.
This markdown file describes authentication with FHIR_CLIENT_SECRET, token exchange, and authorized FHIR requests, all of which involve sensitive credentials and access to protected health data. Under the markdown-file warning criterion, the documentation should clearly disclose privacy and system-impact implications of sending patient data and secrets to external services.
The skill declares environment-variable and network-dependent behavior but provides no explicit tool-scope or permission boundaries. In a healthcare context, undeclared network/env access is dangerous because the agent may access secrets and transmit patient data to external services without clear user-visible authorization controls.
Although the manifest says the skill is for documentation only and not diagnosis or prescribing, the example SOAP output includes assessment and plan content that can function as clinical recommendations. In clinical workflows, this can overstep the stated safety boundary and encourage reliance on generated medical judgment, creating patient-safety and liability risk.
The skill explicitly supports sending requests to an external hosted backend, and elsewhere states that patient context may be transmitted for generation. In a healthcare setting, external transmission of clinical context creates significant PHI exposure risk if the endpoint, retention, encryption, access controls, and BAA status are not strictly controlled and transparently enforced.
Set these variables to enable:
export CLINICAL_DOC_API_URL="https://api.yourdomain.com/v1"
export CLINICAL_DOC_API_KEY="your-api-key"
The manifest describes a skill for drafting and retrieving clinical documentation via FHIR/manual input, with explicit documentation-only scope. This backend also exposes account usage tracking and Stripe-based credit purchasing endpoints, which are product monetization features not described as part of the skill's behavior.
The code sends structured patient context to an external LLM provider, but the skill description does not clearly disclose that protected health information may leave the system boundary. In a healthcare documentation context, undisclosed third-party transmission of patient data materially increases privacy, compliance, and trust risk.
The comment asserts that no PHI is stored after the LLM call, but the code does not enforce deletion, prevent downstream logging, or verify retention behavior by dependencies and providers. In a clinical setting, unsupported privacy guarantees can mislead operators into handling PHI less cautiously than required.
Patient context is transmitted over the network to an external LLM service without any evident user-facing warning or consent step in this backend flow. Because the skill handles clinical documentation, this creates significant confidentiality and regulatory risk if users assume processing stays within their EHR or local environment.
The AVS branch instructs the model to format output "in plain English," which imposes a specific language choice. Under the policy, language constraints should not be forced without user opt-in or a clearly documented, justified locale limitation.
The external call to api.anthropic.com is itself expected functionality, but in this application it represents outbound transmission of clinical content to a third party. The danger arises from the combination of healthcare data, insufficient disclosure, and lack of visible minimization or consent controls rather than the mere existence of an HTTP request.
async with httpx.AsyncClient() as client:
response = await client.post(
"https://api.anthropic.com/v1/messages",
headers={
"x-api-key": api_key,
"anthropic-version": "2023-06-01",
The manifest describes pulling structured patient data from FHIR and generating documentation drafts. The prior authorization section adds a separate capability: 'looks up the requested item's typical HCPCS/CPT code,' which is not described in the manifest and is not a direct FHIR retrieval behavior.
No suspicious patterns detected.