Back to skill

Security audit

Health Assistant

Security checks for vulnerabilities and agentic risk

Overview

This health skill is broadly coherent, but it asks for and stores sensitive medical information with weak disclosure, unclear controls, and some unsafe location-specific health guidance.

Review this skill carefully before installing. It keeps health data local and does not appear to exfiltrate data, but it may store sensitive medical details in plaintext under your home directory, and its medical, emergency, mental-health, and travel-regulation guidance should not be treated as professional advice or a substitute for local emergency services.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/health_manager.py:13
Finding

Sensitive health data is stored in plaintext files without enforced restrictive permissions

Content
View full analysis

Vulnerability Details

File Locations:

  • scripts/health_manager.py:13-31
  • scripts/health_storage.py:12-27

Vulnerability Type: Sensitive data exposure through insecure file permissions and plaintext storage
Risk Level: Medium

Vulnerable Code

scripts/health_manager.py:13-31:

python
DATA_DIR = Path.home() / ".health_data"

def init_storage():
    """Initialize storage directory and default files"""
    DATA_DIR.mkdir(exist_ok=True)
    
    files = {
        "profile.json": {},
        "medications.json": [],
        "reminders.json": [],
        "records.json": [],
        "goals.json": {
            "daily_steps": 10000,
            "daily_water": 8,
            "daily_sleep": 8,
            "weekly_exercise": 150
        }
    }
    
    for filename, default in files.items():
        path = DATA_DIR / filename
        if not path.exists():
            with open(path, 'w') as f:
                json.dump(default, f, indent=2)

scripts/health_storage.py:12-27:

python
DATA_DIR = Path.home() / ".health_data"

def init_storage():
    """Initialize storage directory"""
    DATA_DIR.mkdir(exist_ok=True)
    
    # Create default files
    for file in ["medications.json", "reminders.json", "records.json", "profile.json"]:
        path = DATA_DIR / file
        if not path.exists():
            with open(path, 'w') as f:
                if "records" in file:
                    json.dump([], f)
                else:
                    json.dump({}, f)

Technical Analysis

Both storage implementations create ~/.health_data and its JSON files using process-default permissions. Neither implementation specifies a restrictive directory mode such as 0700, a file mode such as 0600, nor repairs permissions on existing storage.

The effective permissions therefore depend on the process umask. With a common umask of 022, ...[truncated 2393 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create the storage directory with owner-only access and repair the mode if it already exists:

    python
    DATA_DIR.mkdir(mode=0o700, parents=True, exist_ok=True)
    DATA_DIR.chmod(0o700)
    
  2. Create new data files with mode 0600. Use os.open where exclusive and explicit creation permissions are required:

    python
    fd = os.open(
        path,
        os.O_WRONLY | os.O_CREAT | os.O_EXCL,
        0o600,
    )
    with os.fdopen(fd, "w", encoding="utf-8") as f:
        json.dump(default, f, indent=2)
    
  3. Correct permissions on existing files after validating that they are regular files owned by the current user:

    python
    if path.exists():
        if path.is_symlink() or not path.is_file():
            raise RuntimeError(f"Unsafe storage path: {path}")
        if path.stat().st_uid != os.getuid():
            raise PermissionError(f"Unexpected file owner: {path}")
        path.chmod(0o600)
    
  4. Use atomic writes to reduce corruption risk. Write to a securely created temporary file in the same directory, set mode 0600, flush and synchronize it, and then replace the destination with os.replace.

  5. Apply the same secure storage helper consistently in both modules instead of maintaining two separate initialization and write implementations.

  6. For deployments with stronger confidentiality requirements, encrypt health records at rest using an authenticated encryption scheme. Store encryption keys in an operating-system credential store rather than alongside the JSON files.

  7. Add automated tests that verify the directory is 0700, files are 0600, symlinks are rejected, ownership is checked, and existing insecure permissions are repaired.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code clearly supports part of the declared scope: personal health tracking, medication management, reminders, simple record analytics, BMI calculation, and a few basic health-status checks. However, the declared description is much broader and presents major capabilities that are absent from the code, including mental health counseling, pet care, travel health prep, first aid, symptom analysis, and international drug regulations. The implemented behavior is primarily a local CRUD-style health tracker with limited rule-based advice, so the description materially overstates what the code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code does not implement a full personal health assistant. It only handles local persistence of health-related data in JSON files under the user's home directory. While this partially supports declared uses like health tracking and medication reminders, it does not provide the many substantive capabilities claimed in the description, such as symptom analysis, health advice, drug regulation lookup, mental health support, travel prep, first aid, or pet care. Additionally, the module accesses local filesystem storage despite no declared permissions, though local storage is a supporting detail rather than the main mismatch. The primary issue is that the declared description substantially overstates the functionality actually present in this code chunk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs collection of highly sensitive health, medication, allergy, and emergency-contact data, and later states it is stored locally, but it does not present a prominent upfront warning, consent flow, retention policy, or access-control guidance. Because this is health data, mishandling can expose medical privacy, facilitate identity abuse, and create regulatory compliance issues.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 673)May include surrounding context.

md
- Thoughts of self-harm

**How to Help:**
- Listen without judgment
- Encourage professional help
- Offer companionship
- Crisis hotline: 400-161-9995 (China)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill describes local JSON/CSV storage and record management but does not declare any explicit tool scope or allowed-tools boundaries. In a health context, undeclared file read/write capability increases the risk of overbroad filesystem access, accidental data exposure, or unauthorized modification of sensitive records.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation guidance is broad enough to activate on many ordinary conversations, which can cause the skill to engage in sensitive health workflows when the user did not intend it. In this context that raises privacy and safety risk because the skill may solicit medical history, medications, or emergency data unnecessarily and provide quasi-medical guidance too aggressively.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Advertising add/edit/delete medication features and local record storage without explicit safeguards creates risk of accidental or unauthorized modification of medication records. In a health setting, corrupted dosage history or deleted medication information can mislead users and contribute to harmful decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Providing a hard-coded China-specific crisis hotline without checking the user's location or explaining regional applicability can misdirect users in urgent mental-health situations. In crisis support, incorrect locality-specific emergency information is safety-relevant and may delay access to appropriate help.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description is extremely broad, covering medical advice, medication guidance, mental health counseling, first aid, international drug regulations, and pet care without clear trigger boundaries or safety constraints. In a health-related skill, this increases the chance the agent is invoked for high-risk medical scenarios beyond its safe operating scope, which can lead to unsafe or misleading guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file provides concise first-aid and symptom guidance that users may act on during urgent situations, but it does not clearly warn that the content is simplified, may be incomplete, and should not be relied on as sole medical direction in emergencies. In the context of a health-assistant skill, abbreviated advice can delay emergency care or lead to incorrect self-treatment, especially where recommendations vary by age, condition, or jurisdiction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document tells users to 'Call Emergency (120)' without noting that emergency numbers differ by country and region. In a travel- and international-health context, a hard-coded number can cause users to call the wrong service or waste critical time during a life-threatening emergency.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a broad personal health assistant covering human and pet health guidance, regulatory information, counseling, and travel/first-aid support. This code is limited to CRUD operations for profile/medications/reminders/records plus simple health metric checks and summaries, so the implemented behavior is materially narrower than the stated skill scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script stores highly sensitive health information in plaintext JSON files under the user's home directory without consent prompts, retention controls, or file-permission hardening. In the context of a health assistant, this increases risk because profile, medication, and records data may be exposed to other local users, backups, malware, or unintended sharing, creating a privacy and compliance problem.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python code stores personal health records under the user's home directory, which is sensitive user data. Although the module has brief docstrings, it lacks any user-facing disclosure such as a confirmation prompt, visible warning, or explicit notice that health information will be persisted locally.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The storage initializer creates medications.json, reminders.json, and profile.json as JSON objects ({}), but add_medication() and add_reminder() later treat the first two files as arrays and call .append(). This is a real integrity/availability flaw: once those code paths are hit, the program will raise runtime errors and fail to store medication or reminder data, which is especially risky in a health-management context where missed or lost reminders can affect user wellbeing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The function writes user-provided health record data to disk, which can affect user privacy. The code contains only an internal docstring and no confirmation prompt, log message, or explicit warning that this action persists sensitive data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This function writes profile information directly to profile.json, potentially replacing prior sensitive user data. There is no visible warning, confirmation, or user-facing logging explaining that profile data will be persisted locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This manifest-style JSON contains substantial natural-language content in both Chinese and English, but it does not document whether the skill should respect the user's preferred language or how language selection is determined. That can create a language/locale policy issue if the skill defaults to one language or switches languages without explicit user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.