Book a 30-minute demo →
Skill scan report

mfds-drug-safety

View on GitHub
14 Low This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern.

What this skill does

Public health safety check using Mfds (Korea Food and Drug Administration) OpenAPI, with an emphasis on drug safety and emergency response based on user symptoms and medication use.

github/nomadamas - Data Exfiltration - 7.1k stars

ThreatsData Exfiltration Configuration Management

Threat analysis

Data Exfiltration1 finding
Configuration Management1 finding

Skill info

Namenomadamas/mfds-drug-safety
Registrygithub
Version44fbaca
PURLpkg:github/NomaDamas/k-skill@44fbaca?skill=mfds-drug-safety
Stars7.1k

Assessments (2)

Data Exfiltration1 finding MEDIUM
MEDIUM

Data Exfiltration via local-llm-review

scripts/mfds_drug_safety.py

The script uses `urllib` to make requests to a proxy server (`k-skill-proxy`) and does not explicitly validate or sanitize the input before sending it. This could allow for unintended data to be sent 
Configuration Management1 finding LOW
LOW

Configuration Management via local-llm-review

instruction.md

The `KSKILL_PROXY_BASE_URL` environment variable is used to configure the proxy URL, but there is no explicit guidance on how to securely manage or validate this configuration. If misconfigured, it co

Badge

Add the Anomity scan badge for mfds-drug-safety to your README.

Anomity Skill Check badge

Markdown
[![Anomity Skill Check](https://anomity.ai/skills/badge.svg)](https://anomity.ai/skills/github/nomadamas/mfds-drug-safety/)
HTML
<a href="https://anomity.ai/skills/github/nomadamas/mfds-drug-safety/"><img src="https://anomity.ai/skills/badge.svg" alt="Anomity Skill Check"></a>
Image URL
https://anomity.ai/skills/badge.svg

How Anomity governs this at runtime

Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.

Book a 30-minute demo to see your own skill inventory.

Methodology and disputes

Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of mfds-drug-safety? Report an issue or request a rescan.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok