Back to skill

Security audit

医学文献检索

Security checks across malware telemetry and agentic risk

Overview

This is a small PubMed literature-search helper with disclosed external search behavior and no executable code or credential handling.

Install this if you want help forming PubMed searches and summarizing biomedical literature. Avoid putting private patient details or sensitive identifiers into search queries, since queries may be sent to NCBI PubMed, and verify medical conclusions against qualified clinical guidance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes very generic phrases such as "search literature," "find papers," and "PubMed," plus broad Chinese equivalents, which can unintentionally match routine user requests and invoke this skill when the user did not explicitly intend it. In a medical context, accidental activation is more concerning because it may steer responses toward biomedical search behavior and evidence synthesis in situations where precision and user intent matter.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.