T09 · Insecure Skill Coding Practices
- Location
core/s2_elderly_guardian_agent.py:76- Finding
Unrestricted Alert Endpoint Enables SSRF and Sensitive Health-Event Disclosure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This elderly fall-detection skill is purpose-aligned, but it handles sensitive health/activity data with weak disclosure, broad persistence, and an unvalidated alert endpoint.
Review before installing. This skill should only be used where the monitored person or authorized caregiver has explicitly agreed to health/activity logging and alert sharing. Configure S2_BUS_ENDPOINT only to a trusted, authenticated local service, and avoid deployment unless retention, deletion, encryption, and recipient controls are defined.
core/s2_elderly_guardian_agent.py:76Unrestricted Alert Endpoint Enables SSRF and Sensitive Health-Event Disclosure
Lines L45-L46 define S2-Elderly-Guardian as a 'space physiological sentinel' that is 'absolutely forbidden' from executing physical operations, but the very next lines describe it emitting a CRITICAL_FALL_DETECTED event that leads to an L1 hub deciding whether to issue an unlock/fail-open command. While indirect, the documented behavior positions the sentinel as the initiating cause of a physical security action, which contradicts the absolute phrasing of the documentation.
The skill markets itself as 'zero privacy invasion' while also directing local persistence of gait-degradation data for future medical research. Health-related behavioral telemetry about elderly users is sensitive data, and retaining it without clear minimization, consent, retention limits, or de-identification creates a real privacy and compliance risk; the misleading claim further increases the chance operators deploy it under false assumptions.
Broadcasting critical fall alerts to a medical platform or smart-home bus is functionally appropriate for the skill, but the documentation provides no explicit warning, consent, authentication, or scoping around external transmission of sensitive health events. In practice, an alert that an elderly person has suffered a critical fall is sensitive medical/status data, and sending it over an IPC or external endpoint without documented safeguards can leak private information or be misrouted.
The skill explicitly instructs local storage of elderly gait-degradation data for future medical research without any user-facing notice, consent flow, retention policy, or privacy safeguards. Because this is health-adjacent data tied to a vulnerable population, silent retention can expose sensitive behavioral profiles and create significant privacy, legal, and misuse risks.
The code persistently writes ADL and fall-related logs containing subject identity, timestamps, and health/activity events to local disk without any visible retention policy, access control, encryption, or declared authorization boundary. In an elderly-care context, these records are sensitive health/behavioral data, so unnecessary local retention increases privacy exposure if the host is shared, compromised, or logs are later repurposed.
The function writes sensitive activity and health-adjacent logs to disk without any consent, notice, or confirmation flow for the monitored subject or operator. In this context, even routine activity records can reveal behavioral patterns and medical events, making undisclosed collection and retention a meaningful privacy risk.
The agent transmits fall-alert data, including a persistent identifier and subject-related emergency message, to an environment-configured network endpoint without any explicit consent, destination validation, or user-facing warning. Because this is health/emergency data, silent exfiltration to a misconfigured or attacker-controlled endpoint could disclose sensitive information or operational metadata.
Multiple user-facing labels and status strings are presented only in Chinese, including the dashboard name, title, module titles, and alert text. Under the policy, forcing a specific language without offering a language or locale choice is a natural-language policy violation unless clearly justified as region-specific, which is not documented here.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
Permission is hereby granted, free of charge, to any person obtaining a copy of this Software for **personal, academic, non-commercial research, and individual home care purposes**. You may modify, run, and evaluate the Software locally within your own private residential spaces.
### 2. Commercial Use & Integrators (Restricted Tier)
**Strictly Prohibited without Explicit Authorization:** Any use of this Software for commercial purposes—including but not limited to system integration (SI), deployment in commercial eldercare facilities, nursing homes, hospitals, real estate projects, or offering the Software as a SaaS/PaaS service—is strictly prohibited without a formal commercial license from Space2.world.
### 3. Identity and Addressing Standards (SUNS & S2-DID)
The algorithms governing the generation of SUNS physical addresses and 22-digit S2-DID identities are proprietary to the S2 ecosystem. You may not extract, reverse-engineer, or establish competing registry networks using these protocols.
This markdown file contains user-facing natural-language content exclusively in Chinese, and nowhere indicates that the skill is region-specific or that users may choose another language. Under the language/locale policy rule, forcing a single language without opt-in can be a policy violation.
The comment suggests that creating an on-disk directory somehow makes storage access legitimate, but the code simply performs local persistence regardless of whether such data collection was authorized. This is dangerous because it normalizes bypassing governance/permission expectations and can mislead reviewers into accepting unauthorized storage of sensitive data.
This is a JSON manifest file, so vague-trigger checks apply. The name describes the skill broadly as an elderly health spatiotemporal dashboard but provides no explicit activation phrases, context limits, or exclusion conditions, making it unclear when this skill should be invoked versus other health or dashboard-related requests.
No suspicious patterns detected.