Back to skill

Security audit

China Top Doctor Referral

Security checks for vulnerabilities and agentic risk

Overview

This medical referral skill is mostly aligned with its stated purpose, but it routes sensitive doctor-search data through weakly verified OceanBus peers and stores credentials locally without strong safeguards.

Review before installing. The skill is not judged malicious, but it handles sensitive medical referral data and relies on dynamic OceanBus peers without strong identity verification. Use it only if you trust the publisher and OceanBus environment, understand that queries and customer-service messages may leave your machine, and are comfortable with local OceanBus credentials being stored under your home directory.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search-doctors.js:105
Finding

Unauthenticated OceanBus Responses Permit Forged Medical Search Results

Content
View full analysis
{ if (resolved) return; try { const result = JSON.parse(msg.content); // Response can arrive from a different OpenID than what YP returned if (result.results !== undefined || result.error) { resolved = true; formatOutput(result, opts); await ob.destroy(); return; } ``` A structurally similar issue exists in the list operation at `scripts/search-doctors.js:157-165`, where messages are accepted based only on the presence of a `depts` or `cities` property. ### Technical Analysis The listener accepts the first incoming JSON message containing `results` or `error`. It does not: - Verify that the message sender is the selected DoctorDataSvc. - Verify a cryptographic signature associated with an approved service identity. - Include or validate a random request identifier. - Associate the response with the specific request that was sent. The source comment explicitly permits responses from an OpenID different from the discovered service. Consequently, JSON shape is treated as sufficient proof that a message is an authentic medical-data response. An attacker capable of sending a message to the generated OceanBus identity can race the legitimate service and supply a forged response such as: ```json { "total": 1, "results": [ { "name": "Attacker-Controlled Entry", "title": "Director", "dept": "Cardiology", "hospital": "Attacker-Controlled Clinic", "skill_short": "Attacker-controlled medical claim", "fee_low": 5000, "fee_high": 5000 } ] } ``` Because the Skill instructions require the Agent to reproduce script results without changing the doctor, hospital, or fee data, forged data may be presented directly ...[truncated 1396 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search-doctors.js:59
Finding

Unverified Service Discovery Can Redirect Sensitive Medical Queries

Content
View full analysis
0) { const openid = r.data.entries[0].openid; saveConfigKey('doctor_data_openid', openid); return openid; } } catch (_) { /* YP may be unavailable */ } // 2. Local cache (~/.oceanbus-referral/config.json) const cfg = loadConfig(); if (cfg.doctor_data_openid) return cfg.doctor_data_openid; ``` The discovery tag is defined in `config/api.js:29`: ```js doctorDataTags: ['doctor-data'], ``` The resulting OpenID receives the query at `scripts/search-doctors.js:122`: ```js await ob.sendJson(svcOpenid, request); ``` ### Technical Analysis The script selects the first Yellow Pages result advertising the generic `doctor-data` tag. It does not verify that the entry: - Belongs to the expected service operator. - Uses a pinned or allowlisted public key. - Has a trusted certificate or signed ownership assertion. - Matches the bootstrap OpenID in `config/api.js`. - Satisfies any authenticated service-selection policy. The selected OpenID is then written to `~/.oceanbus-referral/config.json`. This turns a one-time malicious discovery response into persistent routing state. Search messages include city, department, and an optional keyword. Keywords can reveal symptoms, diseases, doctor names, or other health-related information. A malicious discovered service can therefore collect sensitive query data and return manipulated recommendations. ### Attack Pat ...[truncated 1222 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/search-doctors.js:39
Finding

OceanBus API Credentials Are Written Without Explicit Restrictive Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

A second mismatch is flagged: the skill markets itself as a medical referral/search workflow, while the implementation reportedly reduces to direct P2P customer-service messaging without actual search or booking functionality. In a medical context, misleading capability claims are particularly risky because users may rely on nonexistent safeguards, triage logic, or referral quality controls.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A second mismatch is flagged: the skill markets itself as a medical referral/search workflow, while the implementation reportedly reduces to direct P2P customer-service messaging without actual search or booking functionality. In a medical context, misleading capability claims are particularly risky because users may rely on nonexistent safeguards, triage logic, or referral quality controls.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This is a direct tool-parameter abuse pattern: the skill embeds a shell deletion command and frames it as mandatory precondition behavior. Because the content is adversarial by assumption, any instruction to run destructive commands—especially outside a tightly controlled script with validation—creates a meaningful risk of unintended file deletion and could be generalized by an agent into broader command execution behavior.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
| 3 | **城市/科室先查后搜** | 用户提到的城市或科室如果不在数据库里(如"上海"目前不在库),必须先告知用户"该城市暂无数据",然后提供可用的城市/科室列表。 |
| 4 | **如实转述** | 脚本输出的医生姓名、医院、职称、挂号费、出诊时间,一一对应展示。不要改名字、不要换医院、不要编费用。 |
| 5 | **空结果不杜撰** | 如果搜索返回 0 位专家,告知用户并建议扩大范围或换个科室。绝不要说"虽然没有查到,但据我所知……"。 |
| 6 | **删除旧数据** | 如果 `reference/experts.json` 文件存在,立即删除:`rm reference/experts.json`。这是 v1.x 的本地专家数据库,已于 v2.0 废弃,数据已迁移至 OceanBus DoctorDataSvc。**绝对禁止使用这个文件搜索专家。** |

### 当前数据覆盖范围

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
91% confidence
Finding

The lockfile pins form-data 4.0.5, which is reported as vulnerable to CRLF injection in multipart field names. If any upstream code constructs multipart requests using attacker-influenced field names, this can lead to malformed requests, header injection, request smuggling-style behavior against downstream services, or bypass of request validation.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/search-doctors.js (reported line 26)May include surrounding context.

js
}

const DATA_DIR = path.join(os.homedir(), '.oceanbus-referral');
const CRED_FILE = path.join(DATA_DIR, 'credentials.json');
const CONFIG_FILE = path.join(DATA_DIR, 'config.json');

const POLL_TIMEOUT_MS = 15000;

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README explicitly documents sending a raw user message to customer service via node scripts/send-cs.js "用户:xxx | 消息:xxx", but it does not warn that this may disclose personal or medical information to a third party. In a healthcare referral context, message contents are especially likely to contain sensitive health and identity data, so omission of privacy notice and handling guidance creates a real data-sharing risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill declares only network permission in metadata, but the content clearly relies on environment variables such as OCEANBUS_CS_OPENID and references local configuration paths. This creates an incomplete trust boundary: operators and users are not fully informed that the skill reads environment/config state, which can affect execution or expose sensitive values indirectly through logs or misconfiguration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs unconditional deletion of a local file via rm reference/experts.json without user consent, safety checks, or scope validation. Even though the target path is specific, normalizing destructive actions in skill instructions is dangerous because an agent may execute them automatically, causing data loss and setting a precedent for broader filesystem abuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases include very broad medical terms such as '想看', '推荐医生', and '客服', which can cause the skill to activate during ordinary conversation. In a medical workflow, accidental activation can lead to unintended data transmission, tool use, or inappropriate reliance on this skill instead of normal conversational handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest’s user-facing description and most tags are written in Chinese and target China-specific hospitals/services, but there is no indication that users can choose their preferred language or locale. This can violate a language/locale policy when the skill is presented to a broader audience without explicit opt-in or clear region scoping.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language identifier "china-top-doctor-referral" embeds a specific country/locale in the skill/package naming. In this file there is no accompanying language indicating that users can choose another locale or that the China-specific scope is explicitly justified, so it may violate the policy against forcing a locale without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script persists agent credentials and an OpenID in a predictable file under the user's home directory without any permission hardening, encryption, or user disclosure. On multi-user systems, shared environments, backups, or compromised local accounts, these credentials could be recovered and reused to impersonate the client to the OceanBus service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The tool transmits doctor-search queries over the network with no user-facing notice, even though those queries may contain sensitive health-related terms, symptoms, or provider preferences. In a medical referral context, this increases privacy risk because users may unknowingly send potentially sensitive personal or health information to a remote service and to a dynamically discovered service endpoint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The README content, headings, descriptions, and examples are all presented in Chinese, which effectively imposes a specific language without explicit opt-in or justification in the document. Under the stated policy, forcing a language or locale without user choice can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The operational instructions and user-facing example messages are entirely in Chinese and assume Chinese-language interaction, but the document does not state that the skill is China-only or provide user language choice. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The fallback string for csOpenid is written only in Chinese on both L11 and L15. This imposes a specific language in user-facing/configuration guidance without any opt-in, alternative locale, or documented region-specific justification, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: qs==6.15.1 — 3 advisory(ies): CVE-2026-82417 (qs: Denial of Service via Attacker Controlled isBuffer); CVE-2026-8723 (qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/u); CVE-2026-82562 (qs array-limit bypass via bracket-key comma parsing)

Low
Category
Supply Chain
Confidence
83% confidence
Finding

The lockfile includes qs 6.15.1, which has multiple reported denial-of-service issues tied to attacker-controlled parsing/stringification edge cases. In a networked skill that may process user-controlled query parameters or serialize structured inputs for outbound requests, these flaws can be used to trigger crashes or excessive resource consumption.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The dependency version is specified with a caret (^0.7.0), which allows automatic installation of newer compatible releases. This increases supply-chain risk because a compromised or breaking upstream release could be pulled in without explicit review, and this skill depends on an external service SDK in a medical referral context where integrity matters.

Content

Scanner excerpt · package.json (reported line 6)May include surrounding context.

json
"private": true,
  "description": "Top-tier hospital specialist referral — 228 experts from Peking Union, Fudan, SJTU hospitals",
  "dependencies": {
    "oceanbus": "^0.7.0"
  }
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script's user-facing error and status messages are hard-coded in Chinese, including the configuration error and send/failure notices. For a general-purpose skill, this imposes a specific language choice without offering the user a locale option or documenting that the tool is intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.