Back to skill

Security audit

symptom-timeline

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it stores symptom logs locally and creates reports, with no evidence of hidden network access or malicious behavior.

Install only if you are comfortable storing symptom and medication history in local plaintext files. Keep symptom_db.json and exported reports out of shared, synced, or version-controlled folders, and review reports before sharing them with a clinician.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly states that symptom entries are stored in symptom_db.json, but it does not warn users that this is sensitive health data kept locally in plain form. Because the skill handles medical symptom history and trigger information, users may unknowingly store protected personal data on shared devices, in synced folders, or in version-controlled directories, increasing the risk of privacy exposure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill documentation describes file read/write behavior and local database storage, but it does not declare any explicit tool scope or permissions boundaries. In an agent ecosystem, missing scope declarations can cause the runtime or user to underestimate the skill's filesystem access, increasing the risk of unintended access to local files or unsafe writes if the implementation is invoked with attacker-controlled paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is designed to store symptom logs, triggers, medications, sleep, and stress data in a local JSON file, which is sensitive health information. The absence of any privacy warning, data handling notice, or guidance about securing the file can lead users to store regulated or highly personal data without understanding retention, local exposure, backups, or shared-machine risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guidance explicitly tells users to export and hand over a report containing symptom history and medications, which are sensitive health data, but it provides no privacy or minimization warning. In a health-tracking skill, this can lead users to disclose more medical information than necessary, retain insecure plaintext exports, or share reports in contexts where confidentiality is not adequately considered.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script persists symptom names, severity, notes, triggers, and timestamps to a local JSON file with no user-facing notice, consent prompt, or guidance about file location and permissions. Because this data is health-related and personally sensitive, storing it silently on disk increases the risk of unintended disclosure through shared accounts, backups, sync tools, or misconfigured filesystem permissions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The export function writes a doctor-ready report containing symptoms, medications, notes, and timestamps to an arbitrary output file without an explicit privacy warning. This can cause sensitive medical information to be saved in insecure or unexpected locations, where it may be exposed to other local users, cloud-sync services, or routine file sharing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.