Back to skill

Security audit

TCM Diagnosis

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent TCM health assistant, but it asks to stay always active and retain consultation-derived medical information without clear user consent or limits.

Review this skill before installing in any agent that has persistent memory or file-writing tools. Use it only when the user explicitly asks for TCM guidance, keep consultation data ephemeral unless the user clearly opts in, and treat all formula or health advice as educational rather than medical care.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
operations/ROLE-TCM.md:4
Finding

Unscoped Persistent Medical Persona Can Hijack Agent Behavior

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
operations/HEARTBEAT.md:45
Finding

Automatic Cross-Session Retention of Consultation Data Enables Memory Poisoning and Sensitive Data Persistence

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (23)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The role is configured as 'always active', which removes any trigger constraints and causes the TCM persona to apply across unrelated conversations. In a medical-adjacent skill, this increases the chance of unsolicited health guidance, role hijacking of safer/general behaviors, and inappropriate advice in contexts where medical framing is unsafe or irrelevant.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

All visible instructions, trigger phrases, and user interaction examples are presented only in Chinese, and the file does not indicate that users may choose another language. Under the language/locale policy, a skill should not force a specific language unless it offers opt-in choice or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The standalone trigger "体质" is too vague and likely to appear in ordinary discussion, which can cause unintended activation of the body-constitution assessment workflow. Because this workflow collects health information and returns medical-style guidance, accidental invocation is more sensitive here than in a non-health skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase "养生" is very broad and commonly used in general wellness conversations, so the skill may activate unintentionally during unrelated requests. In a medical-adjacent assistant, accidental activation can steer users into symptom collection or health guidance they did not explicitly request, increasing the risk of inappropriate advice or confusion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language instructions, description, and example invocations are entirely in Chinese, and the usage examples imply Chinese-only interaction without stating that language selection is optional. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation phrases are extremely broad, including generic medical terms like '看病' and '问诊' and even broader wellness terms like '食疗' and '养生'. In a conversational agent, these common phrases can cause unintended activation during ordinary discussion, leading the skill to enter a diagnostic workflow unexpectedly and potentially surface medical-style advice in the wrong context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire identity and operating instructions are written in Chinese and define the assistant's role, behavior, and outputs in that language, but there is no indication that users may choose another language or opt in to Chinese-only interaction. This can violate the language/locale policy for skills that should not force a language without user choice or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file is entirely written in Chinese and defines the interaction model only in that language, without offering language selection or opt-in. This can cause users to receive or accept health-related guidance they do not fully understand, increasing misunderstanding risk in a sensitive medical-advice context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation trigger uses the everyday term "养生" as a mode switch without defining scope, confirmation, or exclusions. Because this is a broad phrase likely to appear in ordinary conversation, it can unintentionally activate a health-advice workflow and steer the interaction into quasi-medical guidance without explicit user intent, which is riskier in a medical-context skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase for the diagnostic skill is the everyday term '看病', which is broad enough to match many ordinary health-related conversations. In a medical-context skill, overly broad invocation can cause unintended activation of diagnostic workflows, leading to unrequested medical guidance or collection of sensitive symptom information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The automatic chaining conditions '四诊完成后自动' and '辨证完成后自动' are underspecified and allow downstream diagnostic and prescription-related steps to run without clear user consent or deterministic gating. In a healthcare skill, ambiguous automation increases the risk of escalating from data collection to analysis and treatment recommendation unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire shared-context file is written in Chinese and presents all project state, task names, and skill descriptions exclusively in that language. There is no indication that the user opted into Chinese or that the skill is restricted to a Chinese-only or region-specific context, which may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases shown in the usage section are extremely broad everyday terms such as “看病”, “体质”, and “食疗”. In a medical assistant context, broad triggers can cause unintended activation during normal conversation, which is more dangerous here because accidental entry into diagnostic or health-guidance flows may lead users to rely on medical-style output without clearly intending to invoke the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases for the diagnosis intake agent are broad enough that ordinary discussion of symptoms or casual mentions of seeking care could invoke a medical-triage workflow unintentionally. In a healthcare-oriented skill, unintended activation is more dangerous than in a generic assistant because it can lead to premature diagnostic questioning, collection of sensitive health data, and medical-style guidance outside a clearly consented clinical interaction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The wellness agent uses vague triggers such as '养生' and '保健', which can appear in many non-request contexts and may cause the agent to activate without deliberate user consent. In this medical/wellness context, unintended activation can steer users into quasi-medical recommendations or personalized health advice when they were not explicitly asking for it, increasing safety and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file’s operational instructions, safety templates, and status/reporting formats are entirely specified in Chinese, with no indication that users may choose another language or locale. This creates a natural-language policy concern because the skill appears to force a specific language rather than offering an explicit language preference or justified regional scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file directs the system to record consultation details, including user/case identifiers, symptom summaries, syndrome judgments, and formula recommendations, and to update a knowledge base after every interaction. In a medical context, this creates a real privacy and data-governance risk because it encourages persistent storage and reuse of sensitive health-related data without any visible consent, minimization, retention, or access-control safeguards.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Repeating that the role is 'always active' reinforces an unrestricted activation model and makes it more likely implementers will treat the persona as globally dominant. In this context, that broad persistence can override context-sensitive safeguards and keep the model in a medical-advice mode even when it should disengage or defer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The startup script presents usage instructions exclusively in Chinese trigger phrases such as "说"看病"" and "说"体质"", which implies the skill expects or directs operation in a specific language. The file does not offer an alternative language option or indicate that Chinese-only operation is an intentional, justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This shell script's user-facing comments and output strings are entirely in Chinese, including status messages and safety notices. The file does not provide any opt-in, locale detection, or alternative language option, which conflicts with the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file consistently uses Chinese for headings, instructions, trigger descriptions, and safety notes, with no indication that users may choose another language. This can violate language/locale policy where skills should not force a language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains only Chinese-language content and does not mention any user opt-in, alternative language availability, or justification for a Chinese-only presentation. Under the policy, forcing a specific language without user choice can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

该文件中的自然语言说明与示例均固定为中文,且未说明是否支持其他语言或允许用户选择输出语言。根据规则,若技能强制特定语言而没有用户 opt-in 或合理且明确记录的区域性限制,属于语言/locale 策略风险。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.