Back to skill

Security audit

tcm-jingfang

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed TCM reference skill, but it is broad enough to generate symptom-based herbal prescription and dosage guidance for serious health conditions.

Review before installing. Use this only as historical or educational TCM reference material, not for diagnosis, prescriptions, changing medication, treating serious symptoms, pregnancy/children/elder care, or urgent conditions. Users should consult a licensed clinician for real health decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill declares activation on broad, common medical and medication-related keywords such as “药方”“中药”“方剂” and generic phrases like “这个病吃什么药,” which can match many unrelated health conversations. In a medical-prescribing skill, accidental invocation is risky because it may route users into quasi-diagnostic or treatment guidance without a clear intent to request this specific TCM formula workflow.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The usage-scenario section defines the skill boundary too loosely around symptom descriptions and asking what medicine to take, without clearly distinguishing it from broader medical triage or general health counseling. Because the skill is designed to provide formula-selection and dosage-oriented TCM content, ambiguous activation boundaries increase the chance of the model engaging in unsafe medical guidance when another workflow or a stronger safety policy should apply.

Missing User Warnings

High
Confidence
98% confidence
Finding
This file provides treatment indications and therapeutic framing for many serious medical conditions, including cancer, stroke sequelae, diabetes, hypertension, GI bleeding, psychiatric symptoms, and pediatric conditions, but the file itself does not contain a clear local warning to seek qualified medical care. In this skill’s context, the content is explicitly meant to help users go from symptoms directly to herbal prescriptions, which increases the chance that users will self-diagnose, delay evidence-based care, or use unsafe remedies for high-risk conditions.

Missing User Warnings

High
Confidence
97% confidence
Finding
This file provides specific diagnostic frameworks, syndrome-to-prescription mappings, and named treatment recommendations (for example linking symptom clusters directly to formulas such as 桂枝汤, 麻黄汤, 承气汤类, 四逆汤, and others) without embedding an immediate safety warning in the content itself. In a skill explicitly designed to take user symptoms and suggest remedies, this can encourage users to self-diagnose and self-medicate, creating a real risk of delayed medical care, inappropriate treatment, adverse reactions, and harm from applying formula guidance without qualified clinical evaluation.

Missing User Warnings

High
Confidence
95% confidence
Finding
This section presents concrete medical and disease-treatment claims, including cancer causation, menstrual physiology, and bleeding management, without an inline warning that the content may be inaccurate, non-evidence-based, or unsafe for self-treatment. In a skill explicitly designed to turn symptoms into herbal prescription suggestions, users may rely on these claims for real health decisions, increasing the risk of delayed diagnosis, inappropriate treatment, or harm from following unsafe guidance.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.