T09 · Insecure Skill Coding Practices
- Location
scripts/run.py:27- Finding
Transmission of Sensitive Health Records to an External Model API Without Data-Minimization Controls
- Content
View full analysis
str: payload = {"model": MODEL, "temperature": 0.0, "messages": [ {"role": "system", "content": system_prompt}, {"role": "user", "content": user_prompt}]} try: req = Request(API_URL, data=json.dumps(payload, ensure_ascii=False).encode("utf-8"), headers={"Content-Type": "application/json", "Authorization": f"Bearer {appkey}"}) resp = urlopen(req, timeout=120) body = json.loads(resp.read().decode("utf-8")) except HTTPError as exc: raise RuntimeError(f"API HTTP {exc.code}") except URLError as exc: raise RuntimeError(f"API unreachable: {exc.reason}") return body["choices"][0]["message"]["content"] ``` ```python def build(data: Dict[str, Any], appkey: str) -> Dict[str, Any]: raw = data if isinstance(data, list) else [data] records = [] for r in raw: records.append({ "systolic": require(r, "systolic"), "diastolic": require(r, "diastolic"), "heart_rate": r.get("heart_rate", ""), "unit": r.get("unit", "mmHg"), "measured_at": r.get("measured_at", ""), "note": r.get("note", ""), }) user_prompt = f"请分析以下血压监测数据:\n```json\n{json.dumps(records, ensure_ascii=False, indent=2)}\n```" text = _call_llm(SYSTEM_PROMPT, user_prompt, appkey) return { "skill": "血压监测记录", "status": "ok", "data": {"record_type": "blood_pressure", "record_count": len(records), "records": records}, "text": text.strip(), } ``` ### Technical Analysis The implementation serializes every parsed blood-pressure record and sends it to the fixed external endpoint `https://maas-api.hivoice.cn/ ...[truncated 1544 chars]- Remediation
View remediation
