Back to skill

Security audit

unisound-sm-doc

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed medical-document LLM helper, but it can send sensitive medical text and an API key to any configured endpoint, so users should review it before installing.

Install only if operators understand that submitted medical text is sent to a remote API. Use de-identified data, keep the API key scoped, and do not let untrusted users or integrations control --api-url, --system-prompt, or --output; pin the endpoint to an approved HTTPS host before using real patient data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run.py:69
Finding

Unrestricted API Endpoint Can Expose Credentials and Sensitive Medical Data

Content
View full analysis
str: payload = { "model": model, "temperature": temperature, "messages": [ {"role": "system", "content": system_prompt}, {"role": "user", "content": user_prompt}, ], } try: req = Request( api_url, data=json.dumps(payload, ensure_ascii=False).encode("utf-8"), headers={ "Content-Type": "application/json", "Authorization": f"Bearer {appkey}", }, ) resp = urlopen(req, timeout=timeout) ``` The destination is exposed as an unrestricted command-line argument: ```python p.add_argument("--api-url", default=DEFAULT_API_URL, help="OpenAI compatible API endpoint") ``` The user-controlled value is passed directly to the request function: ```python out["answer"] = call_llm( api_url=args.api_url, model=args.model, appkey=args.appkey, system_prompt=args.system_prompt, user_prompt=user_prompt, temperature=float(args.temperature), timeout=int(args.timeout), ) ``` ### Technical Analysis The `--api-url` option accepts an arbitrary URL without validating its scheme or hostname. `call_llm` then sends an `Authorization: Bearer` header containing the supplied application key and a request body containing the medical question to that destination. Consequently, anyone able to influence the script's invocation or configuration can redirect the request to an attacker-controlled server. The implementation does not require HTTPS and does not rest ...[truncated 1790 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose suggests a specialized local medical entity-extraction skill, but the described behavior is effectively a generic prompt-forwarding client to a remote LLM with broad input handling. This mismatch can cause users to provide sensitive medical records under false assumptions about processing locality, minimization, and task constraints, leading to unintended disclosure or misuse of patient data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script sends the full medical question content, and may also include metadata in its output flow, to a remote third-party API endpoint for processing without any built-in consent prompt, redaction step, or explicit safeguard for potentially sensitive medical information. In a medical-record extraction skill, inputs are especially likely to contain PHI/PII, so external transmission materially increases confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares no explicit tool scope or permission boundary despite behavior indicating file read, file write, and network access. In a medical-document context, this is risky because operators may assume a narrow extraction-only capability while the implementation can read local files and transmit sensitive patient prompts to a remote API.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file description and built-in prompts are written to enforce Chinese-language behavior, and the tool does not present any language selection or opt-in mechanism. This creates a natural-language policy concern because the skill effectively forces a specific language/locale by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.