Back to skill

Security audit

unisound-treatment-process

Security checks for vulnerabilities and agentic risk

Overview

This medical-record summarizer is not clearly malicious, but it needs Review because it can redirect sensitive records and an API key to any configured endpoint and can save plaintext intermediate medical text.

Install only in an environment approved for medical records. Use de-identified inputs, do not override --base except to a trusted HTTPS endpoint, avoid passing reusable credentials on command lines where process arguments may be logged, and do not use --save-prepared unless plaintext retention of medical text is explicitly approved.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run.py:171
Finding

Configurable LLM Endpoint Can Disclose Medical Records and API Credentials

Content
View full analysis
str: url = f"{base.rstrip('/')}/chat/completions" headers = {"Authorization": f"Bearer {appkey}"} if appkey else {} payload = { "model": model, "messages": [{"role": "user", "content": prompt}], "temperature": 0, } response = _http_post(url, payload, headers, timeout=timeout) try: return str(response["choices"][0]["message"]["content"]).strip() except (KeyError, IndexError, TypeError) as exc: raise RuntimeError(f"Unexpected LLM response: {response}") from exc ``` ```python parser.add_argument("--base", default=DEFAULT_LLM_BASE, help=f"内部大模型 base URL(默认:{DEFAULT_LLM_BASE})。") parser.add_argument("--model", default=DEFAULT_LLM_MODEL, help=f"模型名称(默认:{DEFAULT_LLM_MODEL})。") parser.add_argument("--timeout", type=int, default=0, help="HTTP 超时秒数;0 表示一直等待(默认:0)。") parser.add_argument("--appkey", required=True, help="必须传入。内部医疗大模型鉴权 key,使用 Bearer 方式认证。") ``` ```python response = run( payload, base=args.base, model=args.model, appkey=args.appkey, timeout=args.timeout, ) ``` ### Technical Analysis The `--base` argument accepts an arbitrary URL without validating its scheme or hostname. `call_llm()` appends `/chat/completions` to that value and sends both of the following to the resulting endpoint: - The complete prompt containing medical record information. - The API key in an `Authorization: Bearer` header. There is no HTTPS-only check, trusted-host allowlist, or validation that the destination is the documented internal medical-model service. A caller who can influence command-line arguments can ...[truncated 1812 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run.py:152
Finding

Optional Debug Output Persists Sensitive Medical Data with Default File Permissions

Content
View full analysis
None: save_dir = Path(output_path).parent if output_path else SCRIPT_DIR.parents[1] / "runs" / "treatment-process" save_dir.mkdir(parents=True, exist_ok=True) prepared_path = save_dir / f"{input_path.stem}.prepared.txt" prepared_path.write_text(payload_to_prepared_text(payload), encoding="utf-8") print(f"Prepared text saved to: {prepared_path}", file=sys.stderr) ``` The documentation states that input and intermediate results are not written to persistent local storage and are destroyed after the invocation, while `--save-prepared` explicitly writes preprocessed records to disk. ### Technical Analysis When `--save-prepared` is enabled, the Skill writes the complete preprocessed prompt or medical record to a persistent plaintext file. `Path.write_text()` creates the file using permissions derived from the process umask rather than explicitly enforcing owner-only access. The file is not encrypted, automatically removed, or governed by a retention policy. Its location can also be influenced through `--output`, because the parent directory of the output path becomes the prepared-file directory. This behavior contradicts the broad privacy assurance in the documentation that intermediate data is not persisted. The option is intentional rather than covert; however, its handling is insecure for protected medical information because users may rely on the stronger no-persistence statement and may not understand the retention or permission implications. ### Attack Path 1. A user or automated workflow invokes the Skill with `--save-prepared`. 2. The Skill preprocesses the medical record, potentially retaining i ...[truncated 947 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:126
Finding

Dependency Installation Instructions Use Unpinned Package Versions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill transmits medical-record content to a remote LLM service but provides no user-facing notice, consent mechanism, or privacy control. Because the data is health information, undisclosed transmission materially increases compliance, confidentiality, and trust risks even if the endpoint is intended to be internal.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill explicitly supports reading local files, writing outputs, and making authenticated network requests to an internal medical LLM API, but it does not declare any tool scope or permission boundaries. In a medical-data workflow, this increases the risk of overbroad file access, unintended persistence of sensitive records, and unauthorized transmission of PHI to network endpoints if the runtime grants more capability than intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description and the entire skill documentation are written exclusively in Chinese, and the skill states it generates 诊疗经过文本 without indicating any option for output language or user locale selection. Under the policy rule for natural-language violations, this constitutes a language/locale restriction unless the skill clearly offers opt-in or documents a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language content throughout the JSON records is entirely in Chinese, with no indication that language selection is optional or that the skill is specifically limited to a Chinese-language context. Under the policy, forcing a specific language without user opt-in is a reportable locale/language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The module documentation and prompt-building logic indicate the skill is designed to generate outputs in Chinese and uses Chinese-only instructions, without offering the user a language or locale choice. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the constraint is clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The debug path saves preprocessed medical record text to local disk, creating plaintext persistence of sensitive health information outside the generation flow. In a medical skill, this increases exposure through accidental retention, insecure filesystem permissions, backups, log collection, or later unauthorized access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Writing prepared medical text to disk without an explicit warning causes sensitive data to persist locally in a way users may not expect. In clinical contexts, unexpected plaintext persistence can broaden the attack surface through workstation compromise, shared accounts, backups, and operational mishandling.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill that outputs structured 诊疗经过文本, implying some guaranteed formatting or schema. However, the code simply sends a prompt to the model, takes response["choices"][0]["message"]["content"] verbatim, prints it, and optionally writes it to disk, with no parsing, validation, or structural enforcement of the result.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Allowing an arbitrary --base override lets the operator send sensitive medical-record content and the Bearer appkey to any attacker-controlled endpoint while the skill is presented as using an internal medical LLM. In this context, the issue is more dangerous because the prompt contains highly sensitive patient data and the Authorization header is forwarded to the chosen host.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.