Back to skill

Security audit

Health Guide

Security checks for vulnerabilities and agentic risk

Overview

This Korean health guidance skill is coherent and disclosed, with no hidden execution or exfiltration found, but users should handle its medical limits and API keys carefully.

Install only if you want a Korean/Korea-oriented health guide. Do not treat its responses as diagnosis or prescription, verify urgent symptoms with local emergency services, and avoid pasting real API keys into shell commands; use environment variables, an OS secret store, or owner-only files with restrictive permissions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:65
Finding

API Keys Stored in Predictable Plaintext Files Without Enforced Access Controls

Content
View full analysis
~/.config/kdca/api_key mkdir -p ~/.config/data-go-kr && echo "YOUR_KEY" > ~/.config/data-go-kr/api_key ``` Related references to the same credential-storage design appear in `playbook.md`, lines 126–132, and `scripts/README.md`, lines 11–13. ### Technical Analysis The documented setup commands place API credentials in predictable plaintext files without explicitly restricting the permissions of either the parent directories or the files. The effective permissions therefore depend on the user's current `umask`. In an environment with permissive defaults, other local users or compromised processes may be able to read the credentials. The instructions also encourage users to substitute a real credential directly into an interactive shell command. Such a command may be retained in shell history, terminal logs, session recording systems, or administrative auditing records. Restricting the resulting file permissions would not remove those secondary copies. No hardcoded real credentials were found in the project. The vulnerability concerns the documented method by which users are instructed to provision future credentials. ### Attack Path 1. A user replaces `YOUR_KEY` with a valid KDCA or data.go.kr API key and executes the documented command. 2. The shell may record the command, including the credential, in its history. 3. The resulting directory and credential file inherit permissions determined by the user's existing `umask`, because the instructions do not enforce restrictive modes. 4. Another local account, a compromised process running on the same host, or an operator with access to terminal-history records obtains the key. 5. The attacker submits unauthorized requests to the correspondi ...[truncated 883 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description and main skill content present the skill as Korean-only medical guidance, including Korean trigger phrases and Korean instructional text, with no indication that users may choose another language. The policy requires flagging language or locale constraints when they are imposed without explicit user opt-in or clear documented justification.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
### 국가건강정보포털 API (질환·증상 정보)
1. [health.kdca.go.kr](https://health.kdca.go.kr) → 오픈API 신청
2. 키 저장: `mkdir -p ~/.config/kdca && echo "YOUR_KEY" > ~/.config/kdca/api_key`

### 식약처 의약품 API (의약품 정보)
1. [data.go.kr/15075057](https://www.data.go.kr/data/15075057/openapi.do) 활용신청 (자동승인)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Nearly all user-facing strings, triggers, and guidance are written only in Korean, and the beginner guide even states a Korea-specific system orientation, but the manifest does not explicitly present this as an opt-in locale choice or clearly document a formal locale restriction. Under SQP-3, forcing a specific language without user opt-in can be a policy issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger set for symptom routing includes broad, natural-language phrases such as general symptom mentions and department recommendation requests, which can cause accidental activation during ordinary conversation. In a medical skill, unintended routing is more dangerous than in low-risk domains because it may surface health guidance or urgency triage when the user did not intend to invoke medical assistance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The disease-information triggers include generic phrases like asking what a condition is, its cause, treatment, or complications, which may appear in normal conversation without a clear healthcare intent. Because this skill provides medical information, misfires could lead users to receive irrelevant or misleading health content and rely on it inappropriately.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The drug-information triggers contain everyday phrases like asking what something is, how to use it, side effects, or whether it is safe to take, which are too vague unless tied to medication context. In a health setting, accidental activation can prompt inappropriate medication guidance and create risk if users interpret the output as personalized advice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The mental-health intent uses short, high-frequency expressions such as feeling depressed, anxious, stressed, or burned out, which are common in casual conversation and may not always indicate a request for mental-health guidance. In this domain the risk is elevated because unintended activation around sensitive mental-health topics can produce inappropriate self-assessment or crisis-adjacent guidance without clear user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The configuration advertises disk-resident API key paths for external health and drug data services but does not disclose to users that requests may leave the local environment or that credentials are being used to access third-party services. While this is not direct key exposure, it creates a transparency and data-handling issue in a medical context where user-entered symptoms, drug names, or health questions may be transmitted externally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This healthcare skill is entirely Korean-language and routes users to Korea-specific emergency and support channels (119, 1339, 1393) without clearly restricting the skill to Korean users or checking the user's locale. In a medical context, this can misdirect users in emergencies or make critical safety instructions unusable for non-Korean speakers, creating a real safety risk rather than a mere UX issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The router is strongly anchored to Korean healthcare systems, phone numbers, agencies, and language assumptions without clearly declaring that locale restriction or asking the user’s region. In a health-advice skill, locale mismatch can produce unsafe or unusable guidance such as wrong emergency numbers, inappropriate referral paths, or irrelevant insurance/checkup information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The symptom and hospital-routing examples are broad enough that ordinary health-related conversation could be captured without strong disambiguation, leading to unintended tool or skill routing. In a medical context, misrouting is more sensitive than in general-purpose skills because it can suppress safer clarification, produce the wrong care pathway, or prematurely delegate to hospital lookup when the user actually needs triage or emergency guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatically switching to Beginner Mode on vague keywords like 'easily,' 'basic,' or 'first time' lacks clear scope boundaries and can override the user's actual medical intent. In this skill, that can degrade response quality or omit more appropriate triage depth, which is risky when users describe symptoms in simplified language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file is entirely written as a Korean output template and labels sections like '항상 출력' ('always output'), which implies the skill may always respond in Korean. The policy requires flagging language or locale constraints when they are imposed without user opt-in or an explicitly documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill guidance is written as Korean-only operational policy, including required response phrasing and mandatory disclaimer instructions, with no indication that users may choose another language. Under the policy rule, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the restriction is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README instructs users to store an API key in a plaintext local file under ~/.config/kdca/api_key without any guidance on file permissions, secret management, or avoidance of accidental disclosure. While this is not an exploit by itself, it promotes insecure credential handling that can expose API keys through weak filesystem permissions, backups, shell mistakes, or inclusion in support artifacts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.