unisound-med-synonym

Security checks across malware telemetry and agentic risk

Overview

This medical terminology tool is coherent and disclosed, but users should avoid sending identifiable patient data to its external model API.

Use this only with a provider and publisher you trust. Provide a dedicated API key, do not override --api-url to an untrusted destination, and de-identify real patient information before submitting questions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The code sends user-supplied medical question content to an external remote API endpoint, and the surrounding flow also returns/stores associated metadata alongside the request context without any built-in disclosure, consent, minimization, or redaction safeguards. In a medical context, prompts can contain sensitive health information, so silent transmission to a third-party or centralized service creates a significant confidentiality and compliance risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal