T09 · Insecure Skill Coding Practices
- Location
references/C8-service.md:147- Finding
Sensitive health-data workflows do not enforce privacy controls before collection and processing
- Content
View full analysis
Vulnerability Details
File Locations:
references/C1-assessment.md:3-9references/C7-community.md:77-81references/C7-community.md:127-133references/C8-service.md:147-152references/C8-service.md:273-279references/index-and-pipelines.md:388-408references/index-and-pipelines.md:466-470
Vulnerability Type: Sensitive-data processing without a mandatory privacy gate
Risk Level: HighRelevant Source Excerpts
Translated excerpt from
references/C1-assessment.md:3-9:text Collect, interpret, and monitor individual health data around the clock, including examination indicators, lifestyle information, and metabolic status. C1-01 Basic examination-data standardization and collection Input: Required examination report in PDF, image, or manually entered form; optional historical examination data and testing institution. Output: A standardized examination-data table containing indicator names, values, units, reference ranges, abnormality flags, and trend directions.Translated excerpt from
references/C7-community.md:77-81:text C7-08 User health-record collection Input: Required user ID and basic health information; optional questionnaire responses, synchronized device data, and historical intervention records. Output: A structured user health record containing health labels, risk level, and preference profile. Dependency: None. AI autonomy: Semi-automatic.Translated excerpt from
references/C7-community.md:127-133:text C7-13 Community activity monitoring Input: Required community structure and raw message or interaction data; optional content calendar and activity-execution records. Output: Activity dashboard, abnormal-fluctuation alerts, and trend analysis. Dependency: C7-05. AI autonomy: Fully automatic.Translated excerpt from
references/C8-service.md:147-152:text C8-21 CRM data entry and maintena ...[truncated 3455 chars]- Remediation
View remediation
Remediation Suggestions
- Make
C8-39a hard prerequisite for every unit that collects, monitors, stores, analyzes, shares, or reports personal or health data. - Add an enforceable pre-processing gate that verifies:
- Explicit informed consent
- Authorized purpose and recipients
- Minimum necessary fields
- Applicable jurisdiction and retention period
- Access roles and sharing restrictions
- Prohibit raw community-message ingestion unless users have been notified and the collection is necessary for a documented purpose.
- Require de-identification or aggregation before community, enterprise, executive, certification, and success-case reporting.
- Define encryption requirements for storage and transmission, including key-management responsibilities.
- Add immutable audit logs for data ingestion, profile changes, CRM updates, exports, disclosures, and deletion.
- Require human approval before sensitive records are transferred between health, CRM, community, and commercial workflows.
- Establish retention schedules and provide procedures for access, correction, export, revocation, and deletion requests.
- Make
