Back to skill

Security audit

unisound-hypertension-missing-bp

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it handles medical-record text and API credentials with broad remote-transmission behavior that needs careful review before use.

Install only in an environment approved for sending de-identified medical-record text to the configured LLM provider. Use a trusted HTTPS endpoint, avoid passing production credentials through command-line arguments where local process inspection is a concern, do not use --save-prepared with sensitive records unless the output location is protected, and keep clinician review for QC decisions because prompt-injection in record text could affect results.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/emr_qc_impl.py:58
Finding

Unrestricted API endpoint can receive bearer credentials and medical-record data

Content
View full analysis
str: payload = {"model": model, "messages": messages, "temperature": 0} resp = _http_post(url, payload, headers, timeout=timeout) ``` The endpoint is supplied through unrestricted command-line arguments in both entry points: ```python parser.add_argument( "--base", default=DEFAULT_LLM_BASE, help=f"LLM base URL (default: {DEFAULT_LLM_BASE}).", ) ``` ### Technical Analysis The application constructs the destination URL directly from the user-controlled `base` value. It does not validate the URL scheme, hostname, port, resolved address, or final destination. The resulting request contains: - The HiVoice bearer credential in the `Authorization` header. - Medical-record content embedded in the LLM messages. - The configured model identifier. Consequently, a malicious or incorrectly supplied `--base` argument can redirect both the credential and sensitive medical data to an attacker-controlled server. Plain HTTP is also accepted, allowing network observers to intercept the request. Because `urllib.request.urlopen` can access destinations reachable from the host, the same behavior can be used to make requests to internal, loopback, or link-local services. The request format is fixed to an HTTP POST, but it still exposes a server-side request forgery surface if an untrusted party can influence launch parameters. ### Attack Path 1. An attacker influences a wrapper script, deployment ...[truncated 1362 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/emr_qc_impl.py:159
Finding

Medical-record content can inject instructions into LLM quality-control prompts

Content
View full analysis
[Medical record] History of present illness: The patient developed thirst one year ago without an obvious cause. Drinking did not relieve it. The patient gained 10 kg and had no polydipsia or polyuria. No related examination was performed. Past medical history: Hypertension for five years, usually treated with oral medication, with poor blood-pressure control. Physical examination: Heart rate 82 beats per minute. [Quality-control result] Defect There is a history of hypertension, but no highest blood-pressure value is recorded. [Medical record] History of present illness: The patient developed thirst one year ago without an obvious cause. Drinking did not relieve it. The patient gained 10 kg and had no polydipsia or polyuria. No related examination was performed. Past medical history: Hypertension for five years, usually treated with oral medication, with poor blood-pressure control. Physical examination: Heart rate 82 beats per minute, blood pressure 150/90 mmHg. ...[truncated 3855 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code sends patient medical-record content from the history, past history, and physical exam fields to an external LLM API endpoint without any visible consent gate, minimization, masking, or local-processing safeguard. In a medical QC skill, this can expose highly sensitive health information to a third-party processor and create regulatory, contractual, and confidentiality risk even if the transport is HTTPS.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This CLI sends preprocessed outpatient medical record text to an LLM via run_qc without any explicit privacy notice, consent check, minimization step, or confirmation at the point of transmission. Because the data is medical/EMR content, this can expose highly sensitive personal health information to a remote model endpoint, making the issue more serious in this healthcare context than in ordinary text-processing tools.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises capabilities that include file read, file write, and network access, but it does not declare any explicit tool scope or permissions boundary in the manifest. In a medical-record processing skill, this is risky because sensitive clinical text and outputs could be accessed, exfiltrated, or written to unintended locations without an auditable least-privilege policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language content of the skill, including its description and usage instructions, is exclusively in Chinese. Under the policy criteria, forcing a specific language without user opt-in can be a locale/language policy violation unless the restriction is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring, CLI description, and all argument help text are written only in Chinese, which imposes a specific language on users. The file does not provide an opt-in, alternative locale, or explanation that the skill is limited to a Chinese-only operational context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The module documentation and embedded prompts are written to enforce Chinese-language outputs such as answering only with Chinese terms like "有" or "无" and producing Chinese QC results. This appears to impose a language choice without any visible option for the user to select locale or language.

Content

No source excerpt is available for this finding.

Ssd 1

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Untrusted patient-controlled record text is interpolated directly into the LLM classification prompt with no delimiting, sanitization, or defensive instruction hierarchy. A malicious or malformed record could include instruction-like content that causes the model to misclassify whether hypertension exists, leading to incorrect downstream QC decisions and reducing reliability of the medical workflow.

Content

No source excerpt is available for this finding.

Ssd 1

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The second-stage QC prompt again embeds untrusted medical-record fields directly into a long natural-language instruction block. Because the model is asked to render the final defect verdict, prompt-injection content placed in the record can steer the result toward '无缺陷' or otherwise distort the explanation, causing missed medical documentation defects in a clinical quality-control context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module docstring, CLI description, and argument help text are all presented only in Chinese, which effectively forces a specific language for interaction. There is no opt-in, locale selection, or explanation that this skill is intentionally restricted to a Chinese-speaking/regional context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.