Back to skill

Security audit

Uplo Healthcare

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate healthcare knowledge connector, but it needs Review because its artifacts conflict on whether patient-level health data is in scope and it exposes broad export/search capabilities for sensitive healthcare context.

Install only after confirming exactly what your UPLO instance indexes and what the API token can read, export, or modify. Use a least-privilege token, restrict export_org_context to authorized administrators, require audit logging and approval for sensitive healthcare materials, and verify the MCP package/version before deployment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The skill documentation explicitly denies access to PHI while the manifest/metadata advertises searches over clinical notes, lab results, prescriptions, and patient pathways, which are typically patient-level records. This mismatch can mislead users, auditors, or calling agents into treating the skill as lower sensitivity than it really is, increasing the chance of inappropriate invocation, insufficient consent checks, or unsafe data handling in a healthcare context.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The file narrows behavior to organizational protocols and reference materials, but the manifest describes patient-record-oriented search capabilities. In a regulated healthcare environment, this kind of scope ambiguity is dangerous because downstream agents and users may make trust and access decisions based on inaccurate documentation, causing exposure of sensitive clinical data or bypass of stronger safeguards expected for patient data workflows.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README advertises access to highly sensitive healthcare data types such as clinical notes, lab results, prescriptions, and patient pathways, but provides no visible warning about PHI handling, privacy obligations, minimum-necessary access, or regulatory controls. In a healthcare context, normalizing broad search and extraction over patient data without explicit safeguards increases the risk of unauthorized disclosure, unsafe deployment, and misuse by downstream users or agents.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documented `export_org_context` capability suggests bulk export of organizational context, which in this skill may include sensitive patient-related, clinical, or internal operational knowledge, yet the README gives no warning about data sensitivity or export restrictions. In a healthcare knowledge-management setting, export features materially increase exfiltration risk because they can aggregate and transfer large volumes of regulated or confidential data in a single action.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The 'When to Use' section is broad and includes sensitive areas such as root cause analyses, credentialing, peer review, deficiency tracking, and compliance matters without clear invocation boundaries or disallowed scenarios. In healthcare, overly broad triggers can cause the skill to be used for privileged, legally protected, or highly sensitive material without sufficient need-to-know validation, especially when paired with tools like context export.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.