Back to skill

Security audit

医疗与医药合规专家

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to run local healthcare table checks, but it also creates a persistent home-directory usage counter and paid-use gate that the main skill documentation does not clearly disclose.

Review before installing if you do not want a skill to create hidden local state or enforce a paid-use limit. The healthcare data checks appear local and purpose-aligned, but users should not treat the outputs as complete compliance certification and should verify any reimbursement, audit, inventory, or appeal conclusions independently.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
Claiming a unified 8-skill compliance gateway without implementing that gateway can cause users to believe broad hospital compliance checks were completed when they were not. In this domain, the surrounding context increases severity because decisions may affect reimbursement, audit findings, stock control, or denial appeals rather than being a harmless product-description error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
Claiming a unified 8-skill compliance gateway without implementing that gateway can cause users to believe broad hospital compliance checks were completed when they were not. In this domain, the surrounding context increases severity because decisions may affect reimbursement, audit findings, stock control, or denial appeals rather than being a harmless product-description error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
Claiming a unified 8-skill compliance gateway without implementing that gateway can cause users to believe broad hospital compliance checks were completed when they were not. In this domain, the surrounding context increases severity because decisions may affect reimbursement, audit findings, stock control, or denial appeals rather than being a harmless product-description error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
Claiming a unified 8-skill compliance gateway without implementing that gateway can cause users to believe broad hospital compliance checks were completed when they were not. In this domain, the surrounding context increases severity because decisions may affect reimbursement, audit findings, stock control, or denial appeals rather than being a harmless product-description error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
Claiming a unified 8-skill compliance gateway without implementing that gateway can cause users to believe broad hospital compliance checks were completed when they were not. In this domain, the surrounding context increases severity because decisions may affect reimbursement, audit findings, stock control, or denial appeals rather than being a harmless product-description error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
Claiming a unified 8-skill compliance gateway without implementing that gateway can cause users to believe broad hospital compliance checks were completed when they were not. In this domain, the surrounding context increases severity because decisions may affect reimbursement, audit findings, stock control, or denial appeals rather than being a harmless product-description error.

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --list # 看覆盖了哪些子问题
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The top-level comments claim all 8 sub-skill engines are included locally, while runtime logic later allows some sub-skills to exist only in a subscription version. This is deceptive capability misrepresentation that can mislead users into trusting the package's completeness and local-only assurances, especially in a healthcare compliance context where missing checks may affect operational decisions.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The file header states the public version does not write any statistics files, but the code persists a usage counter in the user's home directory. This undermines trust and privacy expectations: users may provide sensitive healthcare-related material believing nothing persistent is written, while the software silently leaves local state behind.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill name, summary, primary descriptions, and trigger phrases are written entirely in Chinese, while the English description is minimal and does not provide equivalent usage guidance. This effectively imposes a specific language/locale on users without opt-in, which matches the language/locale policy violation criteria.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes very generic terms such as '免费', '对账', and '核对', which can match many unrelated healthcare or finance requests and cause this skill to activate unintentionally. In a routing system, this can misclassify user intent, expose sensitive uploaded tables to the wrong analyzer, or produce compliance conclusions outside the intended scope.

Vague Triggers

Medium
Confidence
95% confidence
Finding
This keyword set again contains broad activators like '免费', '对账', and '核对' without clear boundaries tied to medical revenue reconciliation. That increases the chance that ordinary accounting or reimbursement discussions trigger the skill, leading to incorrect routing and possibly processing sensitive billing data under the wrong logic.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The DRG settlement subskill includes non-specific keywords such as '对账' and '核对', which are common across many business workflows. Without stricter scope controls, unrelated reconciliation tasks may be routed here, causing wrong DRG-related conclusions or accidental handling of medical settlement records in an unintended workflow.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Although several terms are domain-specific, the set still contains ambiguous triggers like '免费' and broad operational phrases that can overlap with other inventory or compliance scenarios. Because this skill handles cold-chain and stock records, unintended activation could route sensitive pharmaceutical logistics data into the wrong check and generate misleading compliance output.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list for supply consumption checking includes generic accounting terms that are not unique to this healthcare inventory use case. That makes accidental activation plausible, especially when users submit any reconciliation-related table, which can lead to wrong analysis paths and mishandling of procurement or department usage data.

Vague Triggers

Medium
Confidence
95% confidence
Finding
This subskill mixes domain terms with broad keywords like '对账' and '核对', creating unnecessary activation surface. Since the skill produces compliance-style conclusions about markup and zero-margin policies, misrouting a table here could create false compliance findings or expose pricing/procurement data to the wrong workflow.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The UDI traceability subskill still accepts generic reconciliation terms that could overlap with many unrelated warehouse or audit tasks. In a medical-device context, accidental activation can result in incorrect traceability assessments or unintended processing of regulated inventory and patient-destination data.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The denial/appeal reconciliation subskill uses generic trigger words in addition to its specific name, making it susceptible to activation on unrelated dispute or reconciliation content. Because this area involves insurance denial amounts and appeal status, misrouting can produce incorrect financial/compliance recommendations and unnecessarily expose sensitive settlement data.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The file’s natural-language instructions, labels, and user-facing guidance are entirely written in Chinese and assume Chinese-language inputs such as the exact table headers to be pasted by the user. There is no indication that the user may choose another language or locale, which can violate language/locale policy when no opt-in is provided.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The file’s natural-language interface, instructions, messages, and sample input are all written exclusively in Chinese, with no indication that the user may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Static analysis

No suspicious patterns detected.