T09 · Insecure Skill Coding Practices
- Location
scripts/gen_initial_record.py:19- Finding
Medical Data Is Transmitted to a Third-Party API Without Implemented De-identification
- Content
View full analysis
str: """ 调用公司接口,生成初诊门诊病历(最终记录)。 """ payload = { "diag_id": diag_id, "dep_time": datetime.now().strftime("%Y-%m-%d %H:%M:%S"), "diag": dialogue, } try: data_bytes = json.dumps(payload, ensure_ascii=False).encode("utf-8") req = urllib.request.Request( url=RECORD_API_URL, data=data_bytes, method="POST", headers={"Content-Type": "application/json"}, ) if timeout and timeout > 0: resp_ctx = urllib.request.urlopen(req, timeout=timeout) else: resp_ctx = urllib.request.urlopen(req) with resp_ctx as resp: body = resp.read().decode("utf-8", errors="replace") ``` ```python with open(input_path, "r", encoding="utf-8") as f: dialogue_text = f.read() print(f"Generating initial visit record from dialogue: {input_path}") # 直接调用生成病历接口 record_text = call_record_api(diag_id=diag_id, dialogue=dialogue_text, timeout=timeout) ``` ### Technical Analysis The complete contents of the supplied dialogue are read from disk and assigned to `dialogue_text`. That value is passed directly to `call_record_api`, inserted into the JSON `diag` field, and transmitted to the external service at: ```text https://shangbao.yunzhisheng.cn/skills/record-gen/gen_record_by_diag_v1 ``` No implementation removes or masks names, telephone numbers, government identifiers, addresses, or other personally identifiable or protected health information before transmission. The preprocessing in `scripts/run.py` normalizes speakers and extracts text but does not perform de-identification. This behavior conflicts wi ...[truncated 1639 chars]- Remediation
View remediation
