Back to skill

Security audit

Personal Genomics

Security checks for vulnerabilities and agentic risk

Overview

This genomics skill is not deceptive, but it handles highly sensitive DNA and medical data with real safety and local-dashboard security concerns that users should review before installing.

Install only if you are comfortable with a local tool reading DNA files and writing derived genetic and medical reports to disk. Store outputs in an encrypted, private directory, avoid importing reports from untrusted sources into the dashboard, and treat all medication, cancer, and disease findings as informational until confirmed by qualified clinicians or genetic counselors.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
dashboard/index.html:1278
Finding

Arbitrary HTML and JavaScript Injection in the Local Dashboard

Content
View full analysis
{ try { data = JSON.parse(e.target.result); renderDashboard(); } catch (err) { alert('Error parsing JSON file: ' + err.message); console.error(err); } }; reader.onerror = () => alert('Error reading file'); reader.readAsText(file); } ``` Parsed values are interpolated directly into HTML: ```javascript function renderStats() { const grid = document.getElementById('stats-grid'); const snps = data.snps_analyzed || data.total_snps || 0; const format = data.format_detected || data.format || 'Unknown'; const criticalCount = (data.critical_alerts || []).length; const highCount = (data.high_priority || []).length; grid.innerHTML = `
${snps.toLocaleString()}
SNPs Analyzed
${format}
File Format
${criticalCount}
Critical Alerts
${highCount}
Remediation
View remediation
... ``` Escape at least `<`, `>`, `&`, U+2028, and U+2029 before embedding, then parse the element’s text content. 5. Add a restrictive Content Security Policy that blocks inline scripts, inline event handlers, and unnecessary outbound connections. Move existing inline JavaScript into a separate bundled file so nonces or hashes can be applied. 6. Add regression tests for payloads containing event handlers, SVG payloads, malformed types, and ``. 7. Treat all imported reports as untrusted, even if they are expected to have been generated locally. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
comprehensive_analysis.py:1305
Finding

Sensitive Genetic Reports Are Written Without Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned and Unhashed Third-Party Dependencies Create Supply-Chain Exposure

Content
View full analysis
=1.5.0 numpy>=1.21.0 # PDF report generation reportlab>=4.0.0 # Optional: for PLINK format conversion # plink2 (install separately via package manager) ``` The documented installation process executes this unconstrained dependency resolution: ```bash # Install via clawhub (recommended) clawhub install personal-genomics # Or clone directly git clone https://github.com/wkyleg/personal-genomics.git cd personal-genomics pip install -r requirements.txt ``` ### Technical Analysis Each Python dependency has only a minimum version and no upper bound, exact pin, lock file, or cryptographic artifact hash. Consequently, two installations performed at different times can install different code even when the audited project files are identical. The audit found no evidence that the currently named packages are typosquatted or intentionally malicious. The risk arises because future releases are accepted automatically and their integrity is not bound to the reviewed Skill version. Python package installation may execute package build logic, while imported dependencies execute with the same account privileges as the analysis process. This is particularly significant because the application processes raw DNA data and generates health reports. A compromised dependency would run inside the process that can read both the input genome and output directory. ### Attack Path 1. The user follows the documented `pip install -r requirements.txt` command. 2. pip resolves the newest available releases satisfying the open-ended `>=` constraints. 3. A future compromised, malicious, or otherwise unsafe dependency release is selected. 4. Package build or runtime code executes with the user’s pr ...[truncated 776 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (111)

Missing User Warnings

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

This section contains chemotherapy-related guidance stating standard 5-FU/capecitabine doses may be contraindicated and recommending specific dose reductions, yet it lacks any explicit safety boundary or instruction that treatment decisions must be made by oncology professionals. In an agent context, presenting this as direct guidance could influence life-or-death cancer treatment decisions and cause fatal undertreatment or toxicity if the genotype, zygosity, or clinical context is misunderstood.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill states that it writes multiple reports to a fixed directory under the user's home folder but does not prominently warn that these outputs contain extremely sensitive genetic and medical information. This is dangerous because users or downstream agents may not realize permanent local artifacts are created, increasing the risk of accidental exposure through shared accounts, backups, sync services, or later exfiltration by other processes.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · dashboard/index.html (reported line 1011)May include surrounding context.

html
</nav>
    
    <main class="container">
        <!-- Initial Load State -->
        <div id="initial-state">
            <div class="card">
                <div class="card-body">

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This dashboard parses attacker-controlled JSON from a local file and inserts many fields directly into the page using innerHTML templates without escaping. A crafted file can supply HTML or script-bearing payloads in fields like gene, rsid, interpretation, recommendations, or ancestry values, leading to DOM XSS in the user's browser despite the privacy claim that analysis stays local.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · dashboard/index.html (reported line 1039)May include surrounding context.

html
<!-- Dashboard Content (hidden initially) -->
        <div id="dashboard-content" class="hidden">
            
            <!-- Overview Section -->
            <section id="overview">
                <div class="stats-grid" id="stats-grid"></div>

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The bulk export routine automatically creates a directory under the user's home folder and writes multiple files containing clinical, ancestry, pharmacogenomic, and raw genomic analysis data without any user-facing warning or approval step. In this skill context, the data is exceptionally sensitive, and bulk creation of predictable local files materially increases the risk of accidental disclosure through shared machines, backups, cloud sync, malware collection, or later misuse by integrated applications.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The function claims to analyze hereditary cancer markers but classifies any present genotype at a listed pathogenic site as a detected pathogenic variant, without determining whether the user's allele actually matches the pathogenic allele. In a hereditary cancer context, this can generate false positive high-risk findings and urgent medical recommendations, which is a safety-critical integrity failure with direct potential for psychological harm and inappropriate medical decision-making.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code explicitly acknowledges that full interpretation requires ref/alt knowledge, yet it proceeds to emit pathogenic findings as though interpretation were complete. This makes the misclassification defect knowingly embedded in a medical-risk analysis workflow, increasing the chance that downstream consumers trust incorrect results as validated hereditary cancer findings.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The carrier detection logic is oversimplified to the point of being unsafe, yet the returned results and summary do not prominently warn users that pathogenic calls may be invalid because allele status was not checked. In a clinical genetics skill, absence of an immediate, explicit user-facing warning materially increases the likelihood of harmful reliance on incorrect cancer-risk output.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code generates medication-safety recommendations such as 'AVOID', dose reductions, and urgent provider messaging without a prominent warning that outputs are informational and not a substitute for clinician review. In the pharmacogenomics context, users may act directly on these recommendations, creating risk of inappropriate treatment changes, delayed care, or harm from incomplete interpretation.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The function classifies drugs as 'safe_medications' and states 'No pharmacogenomic interactions detected based on available data,' which is likely to be interpreted as overall medication safety. Because the database is incomplete and only covers pharmacogenomic interactions, this can create false reassurance and cause dangerous non-detected issues to be overlooked.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module generates opioid dose-adjustment guidance from COMT and OPRM1 genotypes, including statements that some users may need higher or lower opioid doses, without any safety disclosure or warning about the uncertainty and clinical risk of such guidance. Opioid dosing is a high-risk medical decision, and presenting genotype-based adjustments without supervision language could contribute to overdose, undertreatment, or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The function returns concrete medication recommendations such as avoiding codeine/tramadol and suggesting alternative opioids, but it provides no user-facing warning that this is not medical advice and no requirement for clinician review. In a genetics-driven pain module, users may act directly on these outputs, creating a realistic risk of unsafe self-medication, inappropriate drug substitution, or delayed professional care.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file embeds actionable pharmacogenomic recommendations such as drug ineffectiveness warnings and consultation triggers directly in code, but provides no explicit disclaimer, clinician-only restriction, or requirement for professional review. If surfaced by an agent as direct advice, users could self-adjust or refuse medications like codeine, tramadol, or tamoxifen based on incomplete genotype interpretation, creating real patient safety risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code includes anticoagulation guidance such as approximate warfarin dose reductions and references to bleeding risk without any warning against acting on this information directly. Because warfarin dosing is highly sensitive and depends on multiple genetic and non-genetic factors, an agent could relay oversimplified recommendations that lead to hemorrhage or thrombosis.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file encodes highly sensitive genetic-disease interpretations together with concrete medical recommendations such as screening, activity restriction, family testing, and treatment-oriented guidance, but it contains no limitation notice, clinical-validation caveat, or requirement for confirmatory testing. In a consumer-facing or automated interpretation pipeline, users could treat these entries as definitive medical advice despite array limitations, incomplete penetrance, marker ambiguity, and the fact that some listed variants are not appropriate for diagnosis from standard consumer genotyping data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file contains direct drug-avoidance instructions such as avoiding aminoglycoside antibiotics based on a genetic marker, but it lacks an explicit warning that such decisions require clinical confirmation and urgent medical judgment. In practice, a user could stop, refuse, or delay medically necessary treatment based on an unverified or misinterpreted result, creating serious patient-safety risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that reports are automatically saved to a persistent directory under the user's home folder and includes highly sensitive outputs such as genetic summaries, pharmacogenomics data, ancestry, and PDF reports. Even though the file emphasizes local processing and no network access, writing these artifacts to disk without an explicit privacy warning or guidance on securing, relocating, or disabling storage can expose protected health information to other local users, backups, sync tools, or compromised endpoints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list is broad enough to activate on many common health, medication, ancestry, and lifestyle discussions, which can cause the agent to invoke a highly sensitive genomics skill without clear user intent. In this context, unintended activation is more dangerous because the skill handles medical and genetic data, potentially leading to over-collection, inappropriate analysis, or disclosure of sensitive inferences.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring says "Advanced DNA Analysis - Haplogroups, PRS, ROH", which describes three analysis categories. The code also performs Neanderthal ancestry marker reporting, blood type prediction, vitamin/mineral metabolism analysis, circadian/sleep marker analysis, and alcohol metabolism analysis, so the documentation understates and misrepresents what the script actually does.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This script processes highly sensitive genetic data and writes richly derived inferences to a persistent JSON file without any explicit consent, warning, or data-handling controls. In the context of a DNA analysis skill, that is especially dangerous because the output includes health-risk estimates, ancestry markers, and other sensitive attributes that could be exposed to other local users, backups, logs, or downstream systems if the reports directory is not properly protected.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module-level privacy claim says analysis runs locally and implies privacy, but the script also creates a persistent reports directory under the user's home folder and stores detailed genetic results there. For highly sensitive genomic data, undisclosed local persistence increases the risk of later exposure through backups, shared accounts, malware, or other local access, making the privacy representation misleading and security-relevant.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script writes multiple highly sensitive genetic reports to disk automatically without an explicit warning or consent step before persistence. Genetic data can reveal health risks, traits, and drug-response information, so silently storing it in a predictable home-directory location materially raises confidentiality risk if the device is shared, backed up, synced, or later compromised.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The docstring states that all analysis runs locally and mentions no network requests, which is true as far as remote transmission goes, but it omits that the script persistently writes sensitive genetic analysis outputs into the user's home directory. In a DNA-analysis context, that omission is security-relevant because users may reasonably infer stronger privacy guarantees and may not expect ancestry and haplogroup data to be stored on disk where other local users, backups, sync tools, or later compromise could expose it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script saves haplogroups and ancestry-comparison results to '~/dna-analysis/reports' automatically, without explicit consent or a warning that highly sensitive genetic information will be persisted. In this skill context, the data is unusually sensitive and can reveal ancestry and familial information, so silent local storage increases the risk of disclosure through shared machines, backups, cloud sync, or later malware/access by another user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.