Back to skill

Security audit

医疗设备问题报告生成器

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently generates medical-device issue-report drafts and does not show hidden data access, network exfiltration, persistence, or destructive behavior.

Before installing, confirm the broad activation keywords fit your workspace; teams discussing issue reports frequently may prefer more explicit invocation phrases. Treat generated severity and medical-device report content as a draft for qualified review, especially for patient-safety or regulatory matters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrase “问题报告” is broad enough to appear in normal conversation, documentation, or user discussion, which can cause unintended skill activation. In a medical-device workflow, accidental invocation may lead to unintended drafting of defect records, misclassification, or confusion in regulated reporting processes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The phrase “缺陷报告” is also generic and can be used in ordinary QA or engineering discussion, making it unreliable as an invocation boundary. This increases the chance that unrelated text is interpreted as a command, especially in collaborative issue-triage contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The English trigger “issue report” is common workplace language and is likely to appear in routine project management conversations. That overlap makes accidental activation plausible, which is risky in environments handling medical-device defects where generated content may be mistaken for formal records.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains generic phrases such as '问题报告', '缺陷报告', and 'bug 报告' that can easily appear in ordinary conversation, causing the skill to activate when the user did not explicitly intend to invoke it. In a medical-device workflow, unintended activation can misroute user input into a structured defect-reporting flow, potentially producing inaccurate records or interfering with other agent behaviors.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation keyword "问题报告" is broad and likely to appear in ordinary conversation, which can cause the skill to trigger outside the user's intended scope. In this context, the skill generates structured medical-device defect reports, so accidental invocation could expose user-provided operational details or cause unintended report drafting, though the package file itself shows no direct exfiltration or code-execution behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The English trigger "issue report" is generic and may activate during normal discussion about bugs, tickets, or QA workflows rather than an intentional request to run this skill. Because the skill operates in a medical-device reporting context, accidental activation may lead to unintended processing of sensitive defect or environment details, increasing workflow confusion and minor data-handling risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese from the title through the checklist. Under the natural-language policy rule, forcing a specific language without user opt-in is a policy concern unless the locale restriction is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing guidance exclusively in Chinese, beginning with the title at L001 and continuing throughout the document. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains natural-language descriptions and runtime messages entirely in Chinese, including the module docstring and CLI error/output text. Because the skill does not provide any user opt-in, fallback language, or explicit justification that it is a Chinese-only regional tool, it violates the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

All user-facing instructions and examples in the README are presented in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking region. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

All user-facing instructions and examples are presented only in Chinese, and the skill description does not indicate that language selection is optional or configurable. Under the policy, a fixed language without user opt-in can be a locale/language constraint issue unless clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.