Chinese Medicine CN

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Chinese medicine education skill with clear medical boundaries, but users should not treat its herb or formula dosage references as personal medical advice.

Install only for educational Chinese medicine reference support. Do not use it to choose herb doses, prepare formulas for treatment, replace medications, handle urgent symptoms, or make pregnancy, child, liver, kidney, or medication-interaction decisions without a licensed medical professional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The skill states it must not provide specific drug dosage advice, yet later templates for herbs and formulas explicitly include dosage fields and gram amounts. In a health-related skill, this contradiction can lead the agent to generate actionable dosing instructions for medicinal substances, increasing the risk of unsafe self-medication, adverse interactions, and harm to vulnerable users.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The skill mandates a medical disclaimer for all health-guidance responses, but multiple response templates omit it, making compliance inconsistent and easy to bypass in practice. In a medical-adjacent context, missing disclaimers can cause users to over-trust educational content as personalized medical advice, especially when the skill discusses symptoms, herbs, formulas, and acupoints.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal