Back to skill

Security audit

孕期搭子 Pregnancy Buddy

Security checks across malware telemetry and agentic risk

Overview

This pregnancy assistant is mostly purpose-aligned, but it needs review because it can silently retain sensitive pregnancy details and send uploaded reports to Tencent Cloud OCR without clear upfront consent or controls.

Review before installing. Only use OCR if you are comfortable with report images, PDFs, URLs, or local files being processed by Tencent Cloud, and avoid uploading identifiers unless necessary. Confirm whether proactive reminders and monthly baby-letter memory are opt-in, how stored pregnancy details can be reviewed or deleted, and treat all medical guidance as informational support rather than a substitute for obstetric care.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The listed triggers include very common phrases such as '我怀孕了', '怀孕', '宝宝', and food or checkup questions that can easily appear in ordinary conversation. In a health-focused skill, overly broad activation increases the chance of unsolicited handling of sensitive pregnancy and medical topics, which can cause privacy issues, confusing context switches, or inappropriate medical-style responses when the user did not intend to invoke this skill.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README advertises photo upload for OCR interpretation of prenatal reports and also mentions browser notifications, but provides no visible privacy, consent, retention, or medical-safety warning. Because this skill handles pregnancy and examination data, users may share highly sensitive health information without understanding where it is processed, stored, or whether the output is non-diagnostic.

Missing User Warnings

Low
Confidence
90% confidence
Finding
The README links to an online PWA demo without warning users that health-related queries, pregnancy timelines, or uploaded report data may be transmitted to an external web service. In this context, users could disclose sensitive reproductive and medical information to a hosted application without informed consent or understanding of the privacy implications.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list includes broad everyday pregnancy-related terms like '怀孕', '孕期', '宝宝', and '产检', which can cause the skill to activate in many unrelated conversations. Because this skill handles sensitive health and emotional topics, accidental invocation increases the risk of collecting private reproductive or medical information without clear user intent.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill instructs the AI to perform hidden automatic checks and proactively use pregnancy status, dates, milestones, and prior conversation history without a clear user-facing notice or consent mechanism. In a pregnancy assistant, this involves highly sensitive health and reproductive data, so silent collection and inference materially increase privacy risk and user surprise.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This is a true safety vulnerability because the file defines proactive pregnancy-care reminders and milestone guidance in a health context without clearly stating that the content is informational only and not a substitute for professional medical advice. Users may rely on the reminders' timing, thresholds, and examples when making care decisions, which is especially risky in pregnancy where delayed or mistaken action can affect maternal or fetal health.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This code transmits user-supplied images or document URLs to Tencent Cloud OCR, which may include highly sensitive medical information such as prenatal reports, ultrasound documents, or personally identifiable health data. In a pregnancy-assistant context, silent third-party transmission is especially sensitive because users may reasonably expect local-only processing unless clearly informed and consent is obtained.

Ssd 3

Medium
Confidence
98% confidence
Finding
The skill explicitly directs the AI to silently remember prenatal results, emotional highs and lows, naming choices, and family details for later reuse in generated letters. This is sensitive health and emotional profiling of a pregnant user, and doing it implicitly creates privacy, retention, and secondary-use risks if the data is exposed, reused unexpectedly, or processed without informed consent.

Ssd 3

Medium
Confidence
92% confidence
Finding
The skill encourages users to upload medical reports for interpretation, which increases collection of sensitive health data and may route images to OCR or external tooling. In the pregnancy context, those reports can reveal reproductive status, fetal health, and other protected medical details, so prompting for upload without clear consent and handling safeguards is risky.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.