Back to skill

Security audit

李可老中医思维操作系统

Security checks across malware telemetry and agentic risk

Overview

This skill is a medical-reference package that can make an agent give exact emergency treatment and toxic-herb dosing instructions, which is high risk despite some disclaimers.

Install only for historical or academic study, not for real diagnosis, dosing, emergency care, cancer treatment, pregnancy, pediatric illness, or medication decisions. Users should not follow the formulas or preparation instructions as medical advice; acute symptoms such as stroke signs, heart failure, collapse, severe infection, poisoning, bleeding, or breathing trouble require licensed emergency medical care.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (36)

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The skill claims to be for learning/reference, but its body gives operational emergency-treatment instructions, concrete high-risk drug doses, and even remote/telephone triage guidance for life-threatening situations. That mismatch can cause users or downstream agents to treat educational content as actionable medical direction, creating a serious risk of poisoning, delayed emergency care, or inappropriate treatment in acute settings.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill contains conflicting directives: one section requires urgent medical escalation and physician supervision, while another instructs the agent not to use standard 'consult a professional physician' safety language and to answer in a forceful, direct style. In practice, this inconsistency can suppress or weaken necessary safety messaging exactly when users need clear escalation, increasing the chance of harmful self-treatment.

Missing User Warnings

High
Confidence
98% confidence
Finding
The README contains extensive high-risk medical guidance, including diagnostic routing, emergency-treatment framing, and extreme dosage details for substances like附子/乌头, before sufficiently strong, unavoidable safety gating. In an AI skill context, this can enable unsafe self-treatment or overconfident agent outputs that may cause serious physical harm, especially because the document repeatedly presents the system as '完全合格,可上线使用' and highly validated.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation triggers are broad enough to fire on common discussions such as dosage questions, chronic disease topics, or general theory, which increases the chance that the skill will activate in casual contexts and inject unsafe medical guidance. Because this skill contains detailed hazardous treatment content, overbroad triggering materially increases exposure and the likelihood of misuse.

Missing User Warnings

High
Confidence
99% confidence
Finding
The file presents repeated case narratives and dosage details for extreme-dose, high-toxicity substances such as附子, 生半夏, 生南星, 生川乌 and麝香 in a way that can be operationalized by a reader, while lacking an immediate, local safety warning near the dangerous content. Because the skill is framed as practical medical reasoning and emergency rescue, users may infer these regimens are actionable, creating a serious risk of poisoning, delayed emergency care, or death if self-applied.

Missing User Warnings

High
Confidence
100% confidence
Finding
This section gives explicit urgent-use administration instructions such as rapid decoction, continuous feeding, and nasogastric administration for a life-threatening condition, which materially enables unsafe real-world use outside clinical supervision. In the context of heart failure and collapse, such instructions can prompt users to substitute unproven toxic treatment for emergency care, increasing the likelihood of fatal delay, aspiration, overdose, or poisoning.

Missing User Warnings

High
Confidence
98% confidence
Finding
The document gives detailed stroke and hemorrhagic emergency treatment protocols, including potent herbs, toxic substances, and acute-care instructions, but the file itself lacks strong, repeated safety warnings, triage guidance, or direction to seek emergency medical care. In the context of an agent skill that may be surfaced to users as actionable advice, this creates a serious risk of delayed hospital treatment, self-medication, poisoning, or use of unsafe regimens in life-threatening conditions.

Missing User Warnings

High
Confidence
99% confidence
Finding
These lines present emergency invasive interventions and administration of hazardous substances for acute brain hemorrhage, including bloodletting/acupuncture and multiple strong agents, without immediate warnings about contraindications, toxicity, sterility, or the need for qualified supervision. A user could interpret this as a practical protocol and attempt dangerous actions during a medical emergency, causing direct harm or delaying evidence-based stroke care.

Missing User Warnings

High
Confidence
97% confidence
Finding
This section minimizes risk by asserting that the regimen has no side effects and reframes severe reactions as expected or therapeutic, despite discussing substances and protocols that can plausibly cause serious toxicity or deterioration. Such reassurance can lower user caution, normalize adverse events, and encourage persistence with dangerous treatment rather than stopping and seeking urgent medical evaluation.

Missing User Warnings

High
Confidence
99% confidence
Finding
This file contains extensive, highly specific treatment instructions for severe conditions such as heart failure, pulmonary fibrosis, shock-like states, pediatric convulsions, tuberculosis, and pregnancy-related complications, including detailed dosages and emergency-style interventions. The skill metadata includes only a general caution, but the file itself lacks prominent, repeated in-file warnings that this is historical/reference material and not actionable medical advice; in context, the presence of large-dose and high-risk substances makes misuse plausibly life-threatening.

Missing User Warnings

High
Confidence
99% confidence
Finding
This file contains extensive cancer-treatment regimens, precise dosing, escalation instructions, and endorsements of highly toxic or dangerous substances without adequate safety framing at the point of use. A user could interpret the content as actionable clinical guidance, leading to delayed evidence-based cancer care, poisoning, overdose, or other severe injury, especially because the material repeatedly presents dramatic cure claims and normalizes extreme dosing.

Missing User Warnings

High
Confidence
99% confidence
Finding
The file contains thousands of lines of highly specific treatment protocols, named formulas, exact dosages, escalation instructions, and strong curative claims for serious conditions such as heart failure, stroke, renal failure, sepsis, cancer, diabetes, and pediatric illness. In the context of an agent skill, this is dangerous because users may treat it as actionable medical guidance and attempt self-treatment with toxic or high-risk substances, especially where the text normalizes very large doses and presents anecdotal success as evidence.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This section gives specific treatment principles, named formulas, and dose ranges for a high-risk toxic herb (附子), including very large and emergency-use dosing, without a prominent, immediate safety warning at the start of the section. Because the skill is framed as an operational perspective for acute and severe illness, users may treat it as actionable guidance and attempt unsafe self-medication or delay emergency care.

Missing User Warnings

High
Confidence
99% confidence
Finding
The hypertension section explicitly advises not to monitor blood pressure closely and to continue a remedy even if blood pressure rises, substituting subjective feelings for objective monitoring. This can directly encourage users to ignore dangerous hypertension, stop or avoid standard treatment, and miss stroke, heart failure, kidney injury, or hypertensive emergency.

Missing User Warnings

High
Confidence
99% confidence
Finding
The cancer section states that patients should avoid radiotherapy and chemotherapy and suggests doing so will generally prolong life, without an immediate warning against replacing evidence-based oncology care. In the context of a medical skill discussing serious disease management, this is highly dangerous because it may persuade users to refuse or abandon potentially life-prolonging treatment.

Missing User Warnings

High
Confidence
96% confidence
Finding
This section presents high-risk medical guidance in a self-study format, including claims that sub-effective doses are ineffective and that delayed use can worsen outcomes, without an immediate, prominent warning to require licensed clinical supervision. In the context of emergency and critical-care TCM content, such framing can encourage self-experimentation or unsafe practitioner imitation, especially around potent herbs and acute illness.

Missing User Warnings

High
Confidence
99% confidence
Finding
This passage gives a concrete emergency-treatment anecdote involving very high-dose aconite (附子150g) in a near-death patient, framed as a successful intervention, but without an immediate warning about toxicity, contraindications, or the need for direct specialist supervision. Because aconite is highly toxic and the example is tied to urgent care, readers may copy a dangerous dose or infer that escalating dosage is lifesaving, creating a severe poisoning risk.

Missing User Warnings

High
Confidence
99% confidence
Finding
This section gives highly actionable emergency dosing and administration instructions for toxic herbs, including very large dose escalation, rapid administration to dying patients, and advice that contradicts conservative modern safety practices. Because the file is framed as an operational reference and the warning is only general and not repeated inline, a user could directly apply these directions and cause poisoning, delayed emergency care, or death.

Missing User Warnings

High
Confidence
98% confidence
Finding
These sections include toxic or irreversible interventions such as large-dose aconite-related prescribing, self-prepared emergency rescue formulas, and instructions for urgent administration in critically ill states. The content is sufficiently specific to be used as a treatment manual, yet it lacks local, unavoidable safety controls and could encourage laypersons to attempt dangerous care instead of seeking licensed medical or emergency help.

Missing User Warnings

High
Confidence
99% confidence
Finding
This range explicitly normalizes dose escalation of poisonous herbs, pursuit of strong drug reactions, and interpretation of adverse reactions as therapeutic rather than dangerous. That combination creates a severe risk of users escalating into toxic exposure while discounting early poisoning signs, which can result in fatal cardiotoxic, neurotoxic, or systemic harm.

Missing User Warnings

High
Confidence
97% confidence
Finding
A very large portion of the document provides detailed formulas, gram-level doses, indications, preparation methods, and acute-treatment workflows for serious diseases. In context, this transforms the skill from historical/educational description into actionable medical protocol content, and the sparse global disclaimer is not enough to mitigate the risk of self-treatment, poisoning, delayed evidence-based care, or harmful interactions.

Missing User Warnings

High
Confidence
98% confidence
Finding
This section gives concrete diagnostic rules and treatment recommendations for potentially serious conditions, including statements such as when to use warming vs. purging formulas and claims that certain common treatments will worsen the patient. Although the broader skill metadata says the content is for learning reference, the flagged section itself presents actionable medical guidance in a way that could be followed directly, including for acute or life-threatening presentations, so users may self-diagnose or delay proper care.

Missing User Warnings

High
Confidence
96% confidence
Finding
This section presents concrete diagnosis-to-treatment mappings for serious conditions such as 亡阳、少阴病 and critically ill patients, including emergency-style recommendations like 破格救心汤、通脉四逆汤 and a specific high dose of 附子150g, in a way that can be read as actionable care guidance. Although the skill metadata and boundary section mention learning-only use and clinician supervision, the file itself lacks a prominent, user-facing warning near the dangerous content directing users to seek licensed medical or emergency care instead of relying on the text.

Missing User Warnings

High
Confidence
99% confidence
Finding
This section gives detailed treatment instructions, named substances, gram-level dosing, repeat dosing frequency, and escalation advice for severe illness and emergency-like symptoms without requiring clinician oversight or urgent conventional medical care. In the context of influenza-like illness and purported severe cases, unsafe self-treatment can delay evidence-based treatment, cause poisoning or adverse reactions, and create life-threatening harm, especially given the unusually high doses and unclear substance names.

Missing User Warnings

High
Confidence
98% confidence
Finding
The document states that pregnant people and high-risk groups may use the preventive method while providing no contraindications, uncertainty, or requirement for professional review. Pregnancy and medically vulnerable populations are precisely the groups where unvalidated remedies and topical/inhaled substances can cause disproportionate harm or delay appropriate prevention and treatment.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.