Back to skill

Security audit

personal-health-manager

Security checks for vulnerabilities and agentic risk

Overview

This health skill is mostly a normal advisor, but it adds automatic cross-session learning that can store sensitive health-adjacent details and influence future behavior without enough user control.

Review this skill before installing. It should be acceptable only if you are comfortable with local persistent learning, and ideally after changes that make memory opt-in, prohibit storing health details, isolate data per user, add deletion/retention controls, and remove automatic SKILL.md rewrite guidance.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
scripts/learner.py:74
Finding

Untrusted User Content Can Poison Persistent Agent State

Content
View full analysis
= THRESHOLD_ERROR: suggestions.append( f"⚠️ 错误「{err}」已出现 {info['count']} 次,建议增加预检/兜底步骤," f"并将经验回写本技能 SKILL.md(lastNote: {info.get('lastNote','')})" ) if data["totalOps"] >= THRESHOLD_OPS: caps = data["capabilityStats"] top = max(caps.items(), key=lambda kv: kv[1]["count"]) if caps else None if top: suggestions.append(f"📈 最常用能力:「{top[0]}」({top[1]['count']} 次),优先打磨其示例与输出质量") low = [k for ...[truncated 3098 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/learner.py:63
Finding

Potentially Sensitive Health-Related Data Is Persisted in Plaintext

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a personal health manager, but the documentation adds a generic self-learning and persistence mechanism that logs usage, stores preferences, and supports behavior beyond the declared health scope. In a health-related context, undeclared retention of user behavior and preferences can lead to collection of sensitive personal or health-adjacent data without informed consent, violating least surprise and expanding the attack/privacy surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes persistent learning, preference storage, and file writes without a clear up-front warning, consent flow, or retention policy. In a health-management skill, this is especially dangerous because users may disclose body metrics, chronic disease information, medications, and report data, and undocumented persistence could store or correlate sensitive personal information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed trigger terms include very generic phrases such as “减肥”, “睡眠”, and “营养”, which can appear in many ordinary conversations unrelated to invoking this skill. The manifest does not provide scope limits, exclusion conditions, or negative examples to clarify when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation introduces a generic learning system that stores usage history, error patterns, and user preferences, which materially changes the skill from a stateless health advisor into a persistent profiling component. Because this skill handles potentially sensitive health discussions, even generic preference/history storage creates privacy and compliance risk if users were not clearly informed and did not opt in.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language instructions explicitly tell the system to retain and reuse user preferences across sessions in a local memory file. Persistent cross-session memory is risky in general, and in a health-assistant context it can capture sensitive habits, conditions, and behavioral patterns, creating privacy, profiling, and unauthorized retention concerns.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example commands reference unrelated capabilities such as resume optimization and price comparison, indicating the embedded learning subsystem is generic and not constrained to the health domain. This suggests possible cross-context reuse and increases the risk that data, patterns, or behaviors from other skills could be mixed into a health skill, undermining scope boundaries and user expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example command stores the user preference 输出语言 with the fixed value 中文, which presents a language preference as the default learned behavior. The file does not pair this with an explicit user choice mechanism or note that other languages are supported based on user preference.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

该文件的模块说明明确表示它是“通用自进化学习模块”,可被“任意 WorkBuddy 技能”调用,且“不依赖任何业务知识,完全技能无关”。而当前技能清单声明的是一个聚焦健康管理、饮食、健身、睡眠、用药提醒等具体健康场景的助手;这种面向任意技能的通用学习/遥测功能并非该健康技能描述中声明的核心行为。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and all user-facing CLI descriptions are written only in Chinese, including usage guidance and output strings. This imposes a single language on users without any opt-in, alternative locale, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.