Back to skill

Security audit

med-critical-disease-review

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its insurance-review purpose, but it needs Review because it handles sensitive medical records with misleading privacy and persistence claims.

Install only if you are authorized to send the medical records to the documented assessment service and to store resulting files locally. Avoid real patient data unless the publisher clarifies de-identification, retention, endpoint allowlisting, credential handling, and output-file protections.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/major_disease_assess.py:72
Finding

Unredacted Medical Records Are Transmitted to a Remote Service

Content
View full analysis
Dict[str, Any]: record = dict(data.get("medicalRecord") or {}) docs = record.get("docs") if not isinstance(docs, list): raise PreprocessError("medicalRecord.docs must be a list.") normalized_docs: List[Dict[str, Any]] = [] for item in docs: if not isinstance(item, dict): continue text = item.get("format_page_text") or item.get("text") or item.get("content") doc_type = item.get("docType") or infer_doc_type(str(text or "")) built = build_doc(str(doc_type), str(text or "")) if built: normalized_docs.append(built) if not normalized_docs: raise PreprocessError("medicalRecord.docs did not contain any usable document text.") record["docs"] = normalized_docs paylo ...[truncated 2154 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/major_disease_assess.py:72
Finding

Arbitrary Assessment Endpoint Can Receive the Bearer Credential and Medical Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/major_disease_assess.py:135
Finding

Sensitive Assessment Data Is Persisted to Disk Despite a No-Persistence Claim

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation describes an 'internal' evaluation interface, but the configured endpoint is a public external HTTPS domain, and the skill also performs undeclared file and network operations. In a medical-insurance context, this is particularly sensitive because users may assume protected internal handling while data and bearer credentials are actually sent to an external service, increasing privacy, compliance, and exfiltration risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documentation describes an 'internal' evaluation interface, but the configured endpoint is a public external HTTPS domain, and the skill also performs undeclared file and network operations. In a medical-insurance context, this is particularly sensitive because users may assume protected internal handling while data and bearer credentials are actually sent to an external service, increasing privacy, compliance, and exfiltration risks.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

md
- **发布约束**:示例输入、运行输出、自测脚本均放在 skill 包外(分别位于 `../data/`、`../runs/`、`../self_tests/`),skill 目录内仅保留可发布的核心文件(`scripts/`、`SKILL.md`、`_meta.json`)。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool scope or permissions, yet the documented behavior includes reading files, writing output files, and making network requests to an external service. This creates a governance and least-privilege gap: operators and users cannot reliably understand or constrain what the skill is allowed to access, which is especially risky given the medical-record context and API-key usage.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
| `pdftotext`(poppler-utils) | 提取 PDF 文本 | 输入为 pdf 且未安装 pypdf 时必须 |
| `tesseract`(含 chi_sim+eng 语言包) | 图片 OCR | 输入为 png/jpg/bmp/tif 等图片时必须 |

安装(Ubuntu/Debian):`sudo apt-get install libreoffice poppler-utils tesseract-ocr tesseract-ocr-chi-sim`

> 仅使用 JSON 输入时,无需安装任何第三方包或外部工具。

Tainted flow: 'text' from pathlib.Path.read_text (line 85, file read) → pathlib.Path.write_text (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/format_assessment_nl.py (reported line 90)May include surrounding context.

python
if args.output:
        out_path = Path(args.output)
        out_path.parent.mkdir(parents=True, exist_ok=True)
        out_path.write_text(text, encoding="utf-8")
    else:
        print(text)
    return 0

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sends structured medical record data to a remote HTTPS endpoint, but it provides no explicit consent prompt, disclosure warning, minimization, or redaction support before transmitting highly sensitive health information. In a medical insurance assessment context, this materially increases privacy and compliance risk because users may unknowingly exfiltrate protected health data to an internal or external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script preprocesses and transmits hospitalization medical records, which are highly sensitive personal health data, to a network assessment API via call_major_disease_assess(...) without any explicit consent prompt, warning, masking, or policy check at the point of transmission. In this skill’s context, the data includes diagnoses and clinical documents for major disease claims review, so accidental or unauthorized exfiltration to an internal or misconfigured endpoint can create serious privacy, compliance, and data-handling risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language content of the skill forces a single language/locale for all users, and the document does not provide an opt-in choice or explain that the skill is intentionally limited to Chinese-speaking users. Under the policy, a fixed language requirement without user choice or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The argparse description includes Chinese text 重大疾病, and the script imports build_natural_language from a module explicitly suffixed _nl, suggesting a fixed natural-language output mode. There is no visible option for users to choose language or locale, which may violate the language/locale policy when not clearly justified or opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The --appkey argument is documented as "LLM API key for Authorization: Bearer <api_key>", but the code sends this value directly in the Authorization header to the major disease assessment API endpoint. This is an intent/documentation mismatch that could mislead operators about what credential is actually required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.