T09 · Insecure Skill Coding Practices
- Location
scripts/medical_qa.py:14- Finding
Undisclosed Transmission of Sensitive Medical Data to a Third-Party Service
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This medical Q&A skill does what it claims, but it sends potentially sensitive health questions to an external service without clear consent or privacy controls.
Review this before installing if users may enter personal health details. The skill should clearly warn that questions are sent to Yunzhisheng, ask for consent, advise users not to include identifying information, and document retention/privacy handling. It is not evidence of malware, but it needs careful privacy disclosure for medical use.
scripts/medical_qa.py:14Undisclosed Transmission of Sensitive Medical Data to a Third-Party Service
The skill documentation indicates a custom script performs outbound network requests to a third-party medical QA API, but the skill manifest does not declare any corresponding tool scope or allowed network capability. This creates a permission-transparency gap: reviewers and hosting platforms cannot reliably enforce or audit the skill’s external data flows, which is especially sensitive because user inputs may contain private health information.
This code performs an outbound HTTP request carrying raw user medical queries to an external endpoint. In the context of a medical QA skill, the transmitted content is likely sensitive personal or health-related information, so external transmission materially increases privacy, regulatory, and third-party data handling risk even though HTTPS is used.
headers = {'Content-Type': 'application/json'}
input_data = {"query": query}
for i in range(3):
response = requests.post(url, headers=headers, json=input_data, timeout=600)
if response.status_code == 200:
response_json = response.json()
status = response_json["status"]
The skill sends user-supplied medical questions to a third-party remote service without any visible consent, disclosure, or data-minimization controls. Because medical questions often contain sensitive health information, this creates a privacy and compliance risk if users do not understand that their data leaves the local system and is processed externally.
Natural-language text in the docstring and the example query are exclusively in Chinese, and the endpoint path also indicates a Chinese medical QA service. There is no indication that users can opt into another language or locale, which can violate language-choice policy when not explicitly justified.
No suspicious patterns detected.