Back to skill

Security audit

Chronic Disease

Security checks for vulnerabilities and agentic risk

Overview

The skill performs a plausible medical-review workflow, but its code contradicts privacy promises by sending unredacted medical text to a configurable model endpoint and saving outputs to disk.

Review this carefully before installing. Use only approved HTTPS model endpoints, do not pass real patient records unless your compliance process allows that endpoint to receive them, and assume outputs may be saved locally in plaintext. The publisher should either implement the promised de-identification and no-persistence behavior or revise the documentation to accurately disclose raw medical-data transmission and saved files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/chronic_disease_review.py:109
Finding

Medical and identifying data is transmitted without the promised de-identification

Content
View full analysis
str: blocks: List[str] = [] for item in ocr_data: file_name = item.get("fileName") or "未知文件" page = item.get("page", "") doc_type = item.get("docType") or "未分类文书" text = item.get("ocrText") or "" blocks.append(f"【{doc_type}】{file_name} 第{page}页\n{text}") return "\n\n".join(blocks) def build_review_user_prompt(*, disease_code: str, review_type: str, ocr_data: List[Dict[str, Any]]) -> str: ocr_text = format_ocr_for_prompt(ocr_data) return f"""请对以下材料进行「{review_type}」,病种:{disease_code}。 材料正文: {ocr_text} 请输出 JSON,字段如下(均为字符串): - final_decision:审核结论,取值为「通过」「不通过」「待补充」之一 - reasoning:审核原因说明,需与结论一致 示例: {{"final_decision": "通过", "reasoning": "..."}}""" ``` ```python content = llm( [ {"role": "system", "content": SYSTEM_PROMPT}, {"role": "user", "content": user_prompt}, ] ) ``` ### Technical Analysis `SKILL.md` states that identifying information is strictly de-identified before being sent to any model or interface. The implementation contains no corresponding redaction or data-minimization stage. `format_ocr_for_prompt()` directly inserts the source filename, document type, page number, and complete `ocrText` into the model prompt. The prompt is subsequently sent to the configured LLM endpoint. Names, identity numbers, phone numbers, addresses, insurance information, diagnoses, test results, and other protected medical data can therefore leave the local environment unchanged. The validation function only verifies the input shape and presence of `ocrText`; it does not detect or remove sensitive fields. ### Attack Path 1. A user supplies an OCR document cont ...[truncated 931 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/chronic_disease_review.py:284
Finding

Sensitive review data is persisted to disk despite a non-persistence guarantee

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/chronic_disease_review.py:48
Finding

Unrestricted model endpoint can receive the bearer credential and medical records

Content
View full analysis
str: payload = {"model": model, "messages": messages, "temperature": 0} resp = _http_post(url, payload, headers, timeout=timeout) ``` ```python parser.add_argument("--base", default=DEFAULT_LLM_BASE, help=f"LLM base URL (default: {DEFAULT_LLM_BASE})") ``` The unified entry point forwards the value without validation: ```python resp = review_chronic_disease( ocr_data, disease_code=disease_code, review_type=args.review_type or "慢病审核", appkey=args.appkey.strip(), base=args.base, model=args.model, timeout=args.timeout, ) ``` ### Technical Analysis The user-controlled `--base` argument is concatenated into the request URL without scheme enforcement or hostname validation. The code then attaches the reusable application key as a bearer token and sends the complete model prompt, which contains medical OCR data. Consequently, the endpoint can be changed from the documented internal medical service to an attacker-controlled host. The implementation also permits a plaintext `http://` destination, allowing credential and medical-data interception on the network. This is particularly dangerous in wrappers, automation systems, or delegated invocations where one party controls endpoint configuration while another party ...[truncated 991 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:124
Finding

Third-party dependency installation instructions are not version- or hash-pinned

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
- **发布约束**:示例输入、运行输出、自测脚本均放在 skill 包外(分别位于 `../data/`、`../runs/`、`../self_tests/`),skill 目录内仅保留可发布的核心文件(`scripts/`、`SKILL.md`、`_meta.json`)。

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code sends OCR medical-record text to a remote LLM endpoint for processing, which is a high-risk data disclosure path because the payload may contain protected health information. There is no user-facing consent, redaction step, data-classification check, or warning before transmission, so operators may unknowingly exfiltrate sensitive patient data to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script sends OCR-derived medical records to an LLM service endpoint specified by base/model parameters, yet provides no explicit disclosure, consent, data-classification guardrail, or endpoint restriction. In this healthcare context, transmitting patient data to a remote service can expose protected health information to third parties or misconfigured internal services, making the privacy risk substantial.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documentation describes capabilities that read local files, write output files, and make network calls to an internal medical model, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization and transparency gap: a caller or platform may not have a clear, enforceable policy boundary for sensitive operations involving medical OCR data and outbound transmission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description and the entire skill documentation are written in Chinese, and examples, outputs, and parameter explanations assume Chinese-language use. The file does not offer a language or locale choice, nor does it clearly justify that the skill is limited to a Chinese-speaking or region-specific deployment context.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
| `pdftotext`(poppler-utils) | 提取 PDF 文本 | 输入为 pdf 且未安装 pypdf 时必须 |
| `tesseract`(含 chi_sim+eng 语言包) | 图片 OCR | 输入为 png/jpg/bmp/tif 等图片时必须 |

安装(Ubuntu/Debian):`sudo apt-get install libreoffice poppler-utils tesseract-ocr tesseract-ocr-chi-sim`

> 仅使用 JSON 输入时,无需安装任何第三方包或外部工具。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The system and user prompts, decision labels, and disease mappings are fixed in Chinese, which forces a specific language/locale behavior. There is no visible opt-in, language selection, or documented justification that this is intentionally restricted to a Chinese-only regional workflow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script writes both the raw response JSON and a natural-language summary to local files by default, even though the skill description only states it returns results. Because the response contains medical-review output and may include raw LLM content derived from OCR medical records, this creates an unexpected persistence channel for sensitive health data on disk, increasing exposure through local compromise, backups, or shared workspaces.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring and output construction indicate the formatter always generates Chinese summaries (for example, labels like '结论', '元信息', '原因'). This is a natural-language policy concern because the skill imposes a specific language/locale and provides no option for user choice or opt-in.

Content

No source excerpt is available for this finding.

Tainted flow: 'text' from pathlib.Path.read_text (line 86, file read) → pathlib.Path.write_text (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/format_review_nl.py (reported line 91)May include surrounding context.

python
if args.output:
        out_path = Path(args.output)
        out_path.parent.mkdir(parents=True, exist_ok=True)
        out_path.write_text(text, encoding="utf-8")
    else:
        print(text)
    return 0

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says the skill takes an OCR result array JSON as input, but this script advertises and implements ingestion of pdf/doc/docx/xls/xlsx/csv/txt and auto-detection/preprocessing before review. That broadens the skill from a JSON review tool into a general document ingestion and OCR-normalization pipeline, which is a semantic expansion of the declared behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code writes sensitive medical OCR data and review outputs to disk without any warning, consent flow, retention control, or protective handling. Because the content involves chronic disease review records, these files may contain highly sensitive health information whose unintended persistence materially raises confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

User-facing argument help and defaults are tied to Chinese labels such as 糖尿病, 高血压, and 慢病审核, and later logic infers and outputs those same locale-specific values. There is no indication that users can opt into another language or locale, which may violate a policy requiring language choice rather than a forced locale.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script persistently writes raw model responses and optionally the prepared OCR medical data to local files by default or via a flag, but this persistence is not surfaced in the stated skill behavior. In a medical-review context, silent local storage of PHI/PII increases exposure through leftover artifacts, broader filesystem access, backups, and accidental sharing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.