Back to skill

Security audit

Metabolic Healing Skill System

Security checks for vulnerabilities and agentic risk

Overview

This markdown-only health-management skill is not malware, but it needs Review because it handles sensitive health data and safety-critical wellness workflows without consistently enforced consent, privacy, and clinical-review gates.

Install only if you are prepared to run it under explicit user consent, clinical oversight, and privacy/compliance review. Do not let it make or imply diagnoses, medication changes, aggressive fasting/keto/supplement plans, or intensive exercise plans without qualified professional approval. Disable or tightly review automatic CRM, health-record, community-monitoring, and safety-rule updates unless you have clear authorization, audit logs, rollback, and retention controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
references/C8-service.md:147
Finding

Sensitive health-data workflows do not enforce privacy controls before collection and processing

Content
View full analysis

Vulnerability Details

File Locations:

  • references/C1-assessment.md:3-9
  • references/C7-community.md:77-81
  • references/C7-community.md:127-133
  • references/C8-service.md:147-152
  • references/C8-service.md:273-279
  • references/index-and-pipelines.md:388-408
  • references/index-and-pipelines.md:466-470

Vulnerability Type: Sensitive-data processing without a mandatory privacy gate
Risk Level: High

Relevant Source Excerpts

Translated excerpt from references/C1-assessment.md:3-9:

text
Collect, interpret, and monitor individual health data around the clock,
including examination indicators, lifestyle information, and metabolic status.

C1-01 Basic examination-data standardization and collection
Input: Required examination report in PDF, image, or manually entered form;
optional historical examination data and testing institution.
Output: A standardized examination-data table containing indicator names,
values, units, reference ranges, abnormality flags, and trend directions.

Translated excerpt from references/C7-community.md:77-81:

text
C7-08 User health-record collection
Input: Required user ID and basic health information; optional questionnaire
responses, synchronized device data, and historical intervention records.
Output: A structured user health record containing health labels, risk level,
and preference profile.
Dependency: None.
AI autonomy: Semi-automatic.

Translated excerpt from references/C7-community.md:127-133:

text
C7-13 Community activity monitoring
Input: Required community structure and raw message or interaction data;
optional content calendar and activity-execution records.
Output: Activity dashboard, abnormal-fluctuation alerts, and trend analysis.
Dependency: C7-05.
AI autonomy: Fully automatic.

Translated excerpt from references/C8-service.md:147-152:

text
C8-21 CRM data entry and maintena
...[truncated 3455 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make C8-39 a hard prerequisite for every unit that collects, monitors, stores, analyzes, shares, or reports personal or health data.
  2. Add an enforceable pre-processing gate that verifies:
    • Explicit informed consent
    • Authorized purpose and recipients
    • Minimum necessary fields
    • Applicable jurisdiction and retention period
    • Access roles and sharing restrictions
  3. Prohibit raw community-message ingestion unless users have been notified and the collection is necessary for a documented purpose.
  4. Require de-identification or aggregation before community, enterprise, executive, certification, and success-case reporting.
  5. Define encryption requirements for storage and transmission, including key-management responsibilities.
  6. Add immutable audit logs for data ingestion, profile changes, CRM updates, exports, disclosures, and deletion.
  7. Require human approval before sensitive records are transferred between health, CRM, community, and commercial workflows.
  8. Establish retention schedules and provide procedures for access, correction, export, revocation, and deletion requests.

T09 · Insecure Skill Coding Practices

Error
Location
references/index-and-pipelines.md:320
Finding

Hazardous nutrition and exercise pipelines omit or delay required medical safety reviews

Content
View full analysis

Vulnerability Details

File Locations:

  • SKILL.md:40-46
  • references/C2-nutrition.md:29-42
  • references/C2-nutrition.md:92-98
  • references/C3-exercise.md:28-34
  • references/index-and-pipelines.md:320-368
  • references/index-and-pipelines.md:442-452

Vulnerability Type: Inconsistent safety dependencies and unsafe pipeline ordering
Risk Level: High

Relevant Source Excerpts

Translated excerpt from SKILL.md:40-46:

text
Safety first: Units involving health interventions must undergo risk
assessment by the C6 safety-review cluster before execution.

Referral first: When C6-23 determines that a referral redline has been
triggered, suspend all non-pharmacological intervention processes and
prioritize the medical-referral pipeline.

Translated excerpt from references/C2-nutrition.md:29-42:

text
C2-04 Low-carbohydrate or ketogenic diet generation
Output: A ketogenic or low-carbohydrate diet with carbohydrate below
50 grams per day, ketone-monitoring advice, electrolyte supplementation,
and adaptation-period guidance.
AI autonomy: Semi-automatic; the generated framework must pass C6-06 safety review.

C2-05 Intermittent-fasting plan design
Input: Preferred fasting type, including 16:8, 5:2, one meal a day,
or alternate-day fasting.
AI autonomy: Semi-automatic; the plan must pass C6-07 safety review.

Translated excerpt from references/C2-nutrition.md:92-98:

text
C2-13 Nutrient-supplement plan design
Input: Examination data such as vitamin D, vitamin B12, and iron;
optional dietary-gap analysis and medication effects.
Output: Supplement type, dose, administration time, medication interval,
and re-examination cycle.
AI autonomy: Semi-automatic; the plan must pass C6-17 overdose review.

Translated excerpts from references/index-and-pipelines.md:320-368 and 442-452:

text
P03 Blood-glucose reversal:
examination data -> insulin
...[truncated 3380 chars]
Remediation
View remediation

Remediation Suggestions

  1. Convert every prose safety requirement into a hard dependency enforced by the orchestration model.
  2. Require C6-07 approval before generating or displaying an intermittent-fasting schedule.
  3. Require C6-06 and, where applicable, C6-10 before generating a ketogenic plan.
  4. Require C6-17 before displaying supplement types, doses, timing, or medication intervals.
  5. Require C6-08 and C6-13 before HIIT or disease-specific exercise prescriptions.
  6. Require medication compatibility and organ-function screening before medicinal-food, supplement, ketogenic, fasting, and intensive exercise recommendations.
  7. Add fail-closed behavior: if required health data or qualified human approval is unavailable, provide only general educational information.
  8. Prevent downstream delivery until the safety-review output has an explicit approved status.
  9. Add automated pipeline validation tests that reject any intervention path lacking the applicable C6 predecessor.
  10. Clearly distinguish plan drafting from authorization to execute, and record the approving professional and review time.

T09 · Insecure Skill Coding Practices

Warning
Location
references/C6-safety.md:188
Finding

Safety-critical medical classification and redline maintenance permit excessive autonomous operation

Content
View full analysis

Vulnerability Details

File Locations:

  • references/C1-assessment.md:28-33
  • references/C1-assessment.md:42-49
  • references/C1-assessment.md:58-65
  • references/C1-assessment.md:82-88
  • references/C6-safety.md:188-195
  • references/index-and-pipelines.md:10-35
  • references/index-and-pipelines.md:176-198

Vulnerability Type: Unsafe autonomy for medical classification and safety-policy modification
Risk Level: Medium

Relevant Source Excerpts

Translated excerpt from references/C1-assessment.md:42-49:

text
C1-06 Dyslipidemia type and severity classification
Input: Lipid data including total cholesterol, triglycerides, LDL-C,
HDL-C, ApoA1, and ApoB.
Output: Dyslipidemia type, severity, risk stratification, and ASCVD risk.
AI autonomy: Fully automatic; AI automatically classifies according to guidelines.

Translated excerpt from references/C1-assessment.md:58-65:

text
C1-08 Blood-glucose abnormality stage determination
Input: Fasting plasma glucose and HbA1c; optional glucose-tolerance,
C-peptide, and postprandial glucose data.
Output: Normal, impaired fasting glucose, impaired glucose tolerance,
prediabetes, or diabetes stage, together with a reversal-window assessment.
AI autonomy: Fully automatic; AI automatically determines the stage
according to ADA standards.

Translated excerpt from references/C1-assessment.md:82-88:

text
C1-12 Metabolic health-profile generation
Output: Integrated health profile, overall A-to-E rating, prioritized
metabolic abnormalities, and reversal-priority recommendations.
AI autonomy: Fully automatic; AI integrates multidimensional data and
generates the comprehensive profile.

Translated excerpt from references/C6-safety.md:188-195:

text
C6-22 Safety-redline list maintenance
Input: Required adverse-reaction report; optional latest clinical
guidelines, regulatory updates, and academic eviden
...[truncated 2884 chars]
Remediation
View remediation

Remediation Suggestions

  1. Change disease-stage classification and safety-redline maintenance from fully automatic to human-approved operation.
  2. Require review and sign-off by an appropriately qualified clinician before classifications affect interventions or referrals.
  3. Make authoritative, version-pinned guideline sources mandatory for C6-22.
  4. Do not permit a single adverse-reaction report to modify shared safety rules directly.
  5. Add data-validation controls for units, reference ranges, population applicability, completeness, duplicate records, and conflicting measurements.
  6. Maintain immutable rule provenance, reviewer identity, timestamps, change rationale, and version history.
  7. Test proposed redline changes against approved positive and negative clinical cases before activation.
  8. Implement staged publication, peer review, and immediate rollback for safety-policy changes.
  9. Label automated medical outputs as preliminary and prohibit definitive diagnostic wording without clinical confirmation.
  10. Isolate user-specific adverse-event handling from global safety-policy updates to prevent cross-user propagation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (29)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill includes automated intermittent fasting plan design, including aggressive modes such as OMAD and alternate-day fasting, without direct user-facing contraindication warnings in the feature description. Fasting can trigger hypoglycemia, hypotension, dehydration, medication timing problems, or disordered-eating harms, especially for people with diabetes, pregnancy, low BMI, chronic illness, or relevant medications.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file describes AI-assisted supplement recommendations with specific dosages, timing, and medication spacing based on lab data, but it lacks a strong user-facing overdose/toxicity warning and does not clearly require clinician or pharmacist review before user action. Incorrect supplement dosing can cause toxicity, worsen underlying conditions, or create dangerous drug-supplement interactions, particularly with iron, vitamin D, B12, or other concentrated products.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file explicitly includes '停药减药可行性评估' and a '停药减药评估流程' without an equally explicit warning that medication changes are safety-critical and must be decided by a licensed clinician. In a metabolic disease context, users may act on generated recommendations involving antihypertensives, glucose-lowering drugs, or urate-lowering therapy, creating real risk of hypoglycemia, hypertensive events, rebound disease, or delayed medical care.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list is extremely broad and includes many common health, nutrition, and wellness terms, making accidental or overly frequent invocation likely. In a health-related skill, unintended activation is more dangerous than usual because users may receive quasi-clinical guidance in contexts where they did not explicitly request this specialized workflow, increasing the chance of inappropriate reliance or workflow misrouting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill describes 24/7 collection, interpretation, and monitoring of highly sensitive health data without any visible privacy notice, consent requirement, retention policy, or warning about handling protected personal information. In a metabolic chronic-disease context, the data includes longitudinal medical indicators and lifestyle patterns, so omission of safeguards increases the risk of overcollection, unauthorized sharing, and unsafe downstream use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill explicitly outputs standardized health examination data in Excel/CSV format but provides no warning that generating files can expose sensitive medical data through local storage, syncing, forwarding, or import into less protected tools. Structured exports are especially risky because they are easy to copy, aggregate, and transmit, which can amplify privacy harm if mishandled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The mental-health assessment section processes PHQ-9/GAD-7/PSS screening data and generates psychological state reports without warning that these outputs are sensitive, non-diagnostic, and may require clinician escalation. This is dangerous because users may treat automated screening as definitive, while the data itself is particularly sensitive and could cause harm if exposed or misinterpreted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill defines user feedback collection and aggregation for health products without any privacy, consent, minimization, retention, or de-identification safeguards. In a metabolic chronic-disease context, feedback may include health status, symptoms, biomarkers, or purchasing behavior, making the omission of sensitive-data handling requirements materially risky.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file describes automated generation of personalized nutrition interventions using sensitive metabolic and health data, but the top-level description does not provide a clear user-facing medical disclaimer or require clinical review before use. In a chronic-disease context, users may over-trust AI-produced plans as medical advice, which can lead to unsafe diet changes, missed contraindications, or delayed professional care.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The TCM dietary therapy and medicinal-food sections recommend condition-targeted ingredients, usage ranges, and compatibility guidance without a clear user-facing warning about limited evidence, variable product quality, and herb-drug interaction risks. Users may incorrectly treat these recommendations as proven or inherently safe, leading to unsafe self-management or interactions with antihypertensives, hypoglycemics, anticoagulants, and other medicines.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown skill defines all inputs, outputs, and operating instructions exclusively in Chinese. Under the policy rule for language or locale constraints, forcing a single language without explicit user opt-in or documented regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill is designed to ingest and analyze highly sensitive health, biometric, lifestyle, and potentially genomic data, yet the specification provides no visible privacy notice, consent boundary, retention rule, or medical-use limitation. In a healthcare context, omission of these controls can lead to unauthorized processing, overcollection, unsafe secondary use, and users treating analytical output as clinical guidance without adequate safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This section explicitly takes in user behavior data and prior attempts, which are health-related personal data, but the skill text provides no privacy notice, consent requirement, retention limit, or handling restriction. In a chronic-disease coaching context, such data can reveal medical conditions and lifestyle patterns, increasing the risk of unauthorized collection, over-sharing across modules, or noncompliant downstream use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Using historical consultation records introduces a stronger privacy risk because those records may contain detailed medical history, symptoms, clinician interactions, and other highly sensitive context. The skill describes automatic generation and matching of Q&A from such records without warning users or defining consent, de-identification, or secondary-use boundaries, creating risk of privacy violations and unintended exposure of sensitive health information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Psychological assessment data is especially sensitive and often subject to heightened confidentiality expectations. Referencing such data as an input to course generation without any warning or safeguards can lead to inappropriate profiling, leakage of mental-health indicators, or use beyond what the user reasonably expects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown skill is written entirely in Chinese and does not indicate that language selection is optional or limited to a China-specific deployment context. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section describes collecting user health profiles, including basic health information, questionnaire responses, device-sync data, and intervention history, but provides no notice of consent, privacy disclosure, retention limits, or access controls. Because the skill is specifically for metabolic chronic disease management, the data is highly sensitive health information, making undisclosed collection and downstream profiling materially risky.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill defines fully automated monitoring of community activity using raw message and interaction data, but does not disclose to users that their communications and behavior will be tracked and analyzed. In a health-focused community, interaction metadata can reveal health status, treatment interests, or risk factors, so silent monitoring increases privacy and profiling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This workflow performs churn-risk profiling and recommends automated outreach without warning users that behavioral data will be used to infer risk and trigger contact. In the context of a chronic-disease health service, such profiling can be intrusive, potentially manipulative, and may expose sensitive inferences about a user's health engagement or condition.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file describes broad automated handling of highly sensitive health and CRM data across intake, monitoring, records, scheduling, and analytics, but does not present any user-facing consent, notice, or data-handling constraints at the point of use. In a healthcare-adjacent workflow, silent collection, transformation, and reuse of sensitive data materially increases privacy, compliance, and misuse risk, especially when multiple modules chain data across functions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

C8-10 states that AI will automatically integrate data and update health records, but there is no requirement for user notification, confirmation, provenance tracking, or rollback. Automatic modification of persistent health records can propagate errors, overwrite clinician or user-provided information, and create downstream safety and compliance problems in later care decisions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

C8-21 enables fully automatic extraction, structuring, tagging, and persistence of user interaction data into CRM systems without warning users that conversations and related health context may be stored and transformed. This creates privacy risk, unexpected profiling, and secondary-use exposure, particularly because CRM data may be accessible to broader business teams than clinical records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly includes '用户数据' for post-certification tracking but does not mention user consent, data minimization, retention, de-identification, or lawful basis for processing. In a health-management context, this is sensitive health-related data, so omitting privacy and consent controls creates real risk of noncompliant collection, secondary use, or overbroad monitoring.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire file is written in Chinese and includes no statement that the skill supports other languages or that Chinese-only operation is intentional and justified for a specific region. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The community operations cluster includes private-domain conversion and repurchase strategy, expert marketing activities, and user retention analysis. These commercialization functions go beyond the manifest's health-management framing and are not obviously necessary for delivering metabolic chronic disease intervention guidance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.