Back to skill

Security audit

醫療病歷結構化助手

Security checks for vulnerabilities and agentic risk

Overview

This is a small, non-executable medical-record summarization skill, but it asks users to input sensitive health records and can generate diagnostic, treatment, and medication recommendations without clear privacy, authorization, or clinical-review limits.

Review before installing for real clinical use. Users should only provide medical records they are authorized to process, remove direct identifiers where possible, and treat any diagnosis, treatment, or medication output as draft support requiring qualified clinician review. The skill should add explicit privacy, compliance, and scope limits before use in regulated healthcare workflows.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly invites users to input outpatient or inpatient medical records, which are highly sensitive health data, but it provides no privacy warning, data-minimization guidance, or handling constraints. In a medical context this increases the risk that users will paste identifiable patient information into a system without understanding retention, disclosure, or compliance implications, potentially causing privacy breaches and regulatory exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description states the skill automatically structures outpatient/inpatient medical records and outputs diagnoses and treatment recommendations, but it does not clearly constrain when the skill should be invoked or under what authorization and supervision conditions. In a medical context, overly broad invocation criteria can cause the system to activate on sensitive health data too readily and produce high-stakes clinical recommendations outside appropriate scope, increasing privacy, safety, and misuse risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing instructions and examples in the skill are written in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill metadata is entirely in Traditional Chinese and targets a Chinese-speaking medical workflow without indicating locale negotiation or user opt-in. While not inherently malicious, forcing a language/locale can lead to misunderstanding of medical outputs, incorrect invocation for users in other locales, and reduced informed use in a safety-critical healthcare setting.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.