Back to skill

Security audit

low-carbon-medicine

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent low-carb diet advisor, but it asks for sensitive health details and gives condition-specific diet or fasting guidance without enough privacy and clinical-safety boundaries.

Review carefully before installing. Treat it as general lifestyle information, avoid sharing unnecessary identifiers or sensitive medical records/photos, and consult a licensed clinician before using it for diabetes, pregnancy, kidney/liver/heart disease, eating-disorder history, acute symptoms, or medication-related decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description and the entire instruction set are written as a Chinese-only consultation skill, and the reply style does not indicate that users may choose another language. This creates a locale/language policy issue because the skill appears to mandate one language without opt-in or alternative selection.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill claims it does not diagnose, but it gives condition-specific dietary regimens, contraindication handling, fasting guidance, and a default meal-scoring framework that can function as individualized medical advice. In a medical/nutrition context, users may rely on this guidance for diabetes, insulin resistance, or medication-sensitive conditions, creating a real risk of harm despite the disclaimer.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly asks for health status, medications, symptoms, and lab-like metrics, and also invites meal photo analysis, all of which may contain sensitive health information. Without an explicit privacy notice, minimization guidance, and handling boundaries, users can be induced to overshare regulated or highly sensitive personal data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.