Back to skill

Security audit

Tmp.9jB577fq6q

Security checks for vulnerabilities and agentic risk

Overview

This health-advice skill is self-contained, but it uses broad medical triggers and includes built-in nutritionist referrals with instructions to work around platform blocking.

Review carefully before installing. The skill does not appear to run code or store data, but users may share sensitive health information, and generated reports may include nutritionist consultation prompts. The platform-blocking workaround instruction should be removed or clarified before broad deployment, and chronic-disease use should stay limited to general education with clear medical escalation.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill presents itself as a free, no-login, no-storage health tool, but later embeds lead-generation content for external nutritionist consultation inside generated reports. That creates a deceptive mismatch between stated purpose and actual behavior, and can steer users discussing sensitive health issues into off-platform contact flows they did not explicitly request.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The report template contains a built-in upsell path to external nutritionist services unrelated to the core function of interpreting reports and giving general wellness guidance. In a health context, this is risky because users may treat the embedded referral as trusted medical-like advice or feel pressured into off-platform engagement while sharing sensitive personal information.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger scope is extremely broad, covering many common health, diet, chronic-disease, and lab-report topics. Overbroad activation increases the chance the skill will intercept unrelated or higher-risk medical conversations, causing users to receive quasi-medical guidance in situations that need tighter routing, clearer consent, or escalation to professionals.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The usage scenarios are ambiguous and expansive, using loosely defined phrases like report interpretation, chronic-disease eating advice, and health evaluation. In context, this ambiguity is more dangerous because the skill operates in a health domain where boundary failures can lead to overreach into medical advice, especially for diabetes, hypertension, or other chronic conditions.

Static analysis

No suspicious patterns detected.