Back to skill

Security audit

medical-qa

Security checks for vulnerabilities and agentic risk

Overview

This medical Q&A skill does what it claims, but it sends potentially sensitive health questions to an external service without clear consent or privacy controls.

Review this before installing if users may enter personal health details. The skill should clearly warn that questions are sent to Yunzhisheng, ask for consent, advise users not to include identifying information, and document retention/privacy handling. It is not evidence of malware, but it needs careful privacy disclosure for medical use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/medical_qa.py:14
Finding

Undisclosed Transmission of Sensitive Medical Data to a Third-Party Service

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documentation indicates a custom script performs outbound network requests to a third-party medical QA API, but the skill manifest does not declare any corresponding tool scope or allowed network capability. This creates a permission-transparency gap: reviewers and hosting platforms cannot reliably enforce or audit the skill’s external data flows, which is especially sensitive because user inputs may contain private health information.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This code performs an outbound HTTP request carrying raw user medical queries to an external endpoint. In the context of a medical QA skill, the transmitted content is likely sensitive personal or health-related information, so external transmission materially increases privacy, regulatory, and third-party data handling risk even though HTTPS is used.

Content

Scanner excerpt · scripts/medical_qa.py (reported line 19)May include surrounding context.

python
headers = {'Content-Type': 'application/json'}
    input_data = {"query": query}
    for i in range(3):
        response = requests.post(url, headers=headers, json=input_data, timeout=600)
        if response.status_code == 200:
            response_json = response.json()
            status = response_json["status"]

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill sends user-supplied medical questions to a third-party remote service without any visible consent, disclosure, or data-minimization controls. Because medical questions often contain sensitive health information, this creates a privacy and compliance risk if users do not understand that their data leaves the local system and is processed externally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language text in the docstring and the example query are exclusively in Chinese, and the endpoint path also indicates a Chinese medical QA service. There is no indication that users can opt into another language or locale, which can violate language-choice policy when not explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.