Back to skill

Security audit

德宝恒生-公司名片

Security checks for vulnerabilities and agentic risk

Overview

This is a static company-profile skill with no executable behavior, though some triggers are broad enough to cause irrelevant activations.

Install only if you want a company-profile lookup for 德宝恒生. Be aware that broad triggers may cause this profile to appear for generic company or medical supply-chain questions; narrowing triggers to company-specific phrases would improve precision.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list is broad and includes generic phrases such as 'who are you', 'company profile', '医疗器械', and '医院信息化', which can activate this skill for queries not specifically asking about this company. That can cause unintended routing, override more appropriate skills, and surface promotional or irrelevant content in response to broad user requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.