Back to skill

Security audit

倪海厦skill·经方中医AI

Security checks across malware telemetry and agentic risk

Overview

This non-executable medical persona skill should go to Review because it can produce actionable diagnosis, dosing, acupuncture, emergency, and serious-disease treatment guidance without adequate safety scoping.

Review carefully before installing. This skill has no apparent code-execution or persistence risk, but it can lead an assistant to give concrete medical, herbal dosing, acupuncture, emergency, and cancer/heart-disease guidance. It should only be used, if at all, as historical or academic reference material with strong safeguards that prevent diagnosis, prescribing, emergency instructions, advice to avoid conventional care, or use of identifiable patient case details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (68)

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
该技能名义上是知识/角色扮演,但主体内容实际包含大规模疾病辨证、方剂选择、剂量、加减法和病例导向治疗方案,已经超出一般参考型 persona 的边界。把这类准临床内容直接做成可调用技能,会让模型在普通对话中产出可操作医疗建议,增加误用和伤害风险。

Context-Inappropriate Capability

Critical
Confidence
99% confidence
Finding
文件包含大量不适合作为普通技能直接提供的医疗干预能力,包括急救、中风/昏迷处理、重症与癌症治疗路径、针灸与方药处置等。这会把模型从信息说明器变成事实上的诊疗/急救指挥器,一旦用户照做,可能导致延误正规急救、错误用药或直接人身伤害。

Intent-Code Divergence

High
Confidence
98% confidence
Finding
文件尾部声明“不能开具体处方或诊断”,但正文前部多处已经给出明确方剂、剂量、证候匹配和处置路径,属于自相矛盾的安全声明。这样的矛盾会误导审查者和使用者,以为技能受限,实际上模型仍会生成可执行医疗建议。

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
技能一方面要求“先检索、不要凭记忆、仅源内回答”,另一方面又设置“常见问题速查(直接回答,无需加载模块)”并内置现成结论。这种设计会绕过原本的检索约束,使模型更容易直接输出预写的医疗结论与建议。

Description-Behavior Mismatch

Medium
Confidence
85% confidence
Finding
The file is presented as a reference-style case collection, but the content repeatedly goes beyond archival or educational material and gives actionable treatment guidance. That mismatch is dangerous because users may treat unverified, case-specific narratives as generally applicable medical instructions.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The module asserts or models remote diagnostic capability and individualized treatment judgment despite being a static knowledge skill. In practice this can cause users to rely on non-clinical, non-validated remote medical advice for serious conditions, delaying legitimate care.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The file includes specific formulas, dosages, and self-treatment instructions that are directly executable by users. In a skill context, this turns a reference corpus into actionable medical guidance, increasing the chance of harmful self-medication or substitution for proper care.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The text uses soft disclaimers like 'do not try this' or 'for reference' while elsewhere strongly instructing, persuading, and detailing treatment actions. Contradictory framing is risky because it gives the appearance of caution while still encouraging unsafe reliance.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The file is framed as a knowledge/interpretation module, but it contains concrete diagnoses, dosing, preparation methods, and treatment instructions that operationalize it as a medical treatment skill. That mismatch is dangerous because downstream agents or users may rely on it for real-world clinical decisions without safety gating, professional oversight, or emergency triage.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The text repeatedly claims specific serious diseases can be treated quickly or directly with the described methods, converting historical commentary into actionable clinical guidance. For an agent skill, this substantially raises the risk of unsafe medical advice, delayed emergency care, and overconfident autonomous recommendations.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The file includes direct management guidance for acute or severe conditions such as heart disease, brain inflammation, abdominal emergencies, liver disease, and cancer. In a skill context, that creates a high-risk path for unlicensed medical triage and intervention recommendations where mistakes can cause severe harm or death.

Context-Inappropriate Capability

High
Confidence
96% confidence
Finding
The content goes beyond description and gives procedural intervention steps such as acupuncture points, bloodletting, moxibustion, topical applications, and fumigation. Those instructions are inherently hazardous when executed by non-professionals or surfaced by an agent without competence checks, contraindication screening, or informed consent.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The document describes itself as reference/interpretation material, but the body acts as an operational treatment manual with judgment calls, interventions, and dosing. That inconsistency makes the skill more dangerous because safety systems or users may underestimate its real capability and trust boundary.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The module is presented as study material for Huangdi Neijing, but it includes concrete treatment recommendations and prescriptive clinical claims. That mismatch increases the chance users treat historical/educational content as actionable medical guidance without appropriate safeguards, especially in a skill surfaced to end users.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
This section contains explicit acupuncture/needling procedure instructions despite the file being framed as extracted lecture material. Procedural invasive guidance can cause bleeding, nerve injury, infection, or delayed emergency care if followed by untrained users.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The skill is described as a historical TCM knowledge persona, yet it provides hazardous real-world invasive medical procedure guidance. That exceeds the justified purpose of the skill and creates a direct path for unsafe self-treatment or amateur treatment of others.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The file includes acute-care/emergency intervention instructions beyond a historical knowledge role, including guidance that could be used during emergencies. Incorrect application in urgent situations can directly increase morbidity by causing harm or delaying appropriate emergency services.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The file self-describes as extracted lecture/detail material, but throughout it shifts into practitioner-style directives and treatment advice. This framing can mislead downstream systems or users into underestimating the operational risk of the content.

Vague Triggers

Medium
Confidence
89% confidence
Finding
激活条件覆盖“讨论中医诊断、治疗思路、健康问题”等宽泛场景,几乎会与普通健康咨询大量重叠,导致高风险医疗 persona 被频繁误触发。由于该技能内含大量处方和急救内容,宽触发会显著放大暴露面。

Missing User Warnings

High
Confidence
97% confidence
Finding
技能前部即引入大量诊疗、方药与急救指引,却没有设置醒目、前置、面向用户的风险警示和禁用边界。对于可能把内容当作现实医疗指导的用户,这种缺失会直接提高误信和照做的概率。

Missing User Warnings

High
Confidence
98% confidence
Finding
The file contains extensive medical case narratives and treatment claims about cancer and other serious diseases, including language that discourages conventional care and promotes specific remedies, but it lacks a clear safety warning that this is not medical advice. In a skill intended to shape responses in a medical domain, users could rely on these claims to delay diagnosis, stop prescribed treatment, or self-administer unsafe interventions, creating a real risk of severe injury or death.

Missing User Warnings

High
Confidence
94% confidence
Finding
The file contains numerous medical case summaries describing diseases, symptoms, ages, dates, and other health-related details, which are sensitive personal data. Even if names are omitted, the combination of dates, conditions, demographics, and narrative context can enable re-identification, and the skill provides no privacy notice, consent basis, or handling guidance.

Missing User Warnings

High
Confidence
95% confidence
Finding
This section contains detailed medical and acupuncture treatment guidance, including intervention claims, contraindication-like tables, emergency steps, and strong efficacy assertions, but it does not include a clear warning that the content is educational only and not a substitute for licensed medical care. In the context of a skill that presents itself as an authoritative clinical framework, users may act on this information directly, delay appropriate treatment, or attempt unsafe self-treatment or treatment of others.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The file instructs the agent to adopt a fixed persona and speech style ('倪海厦口述表达方式') with strong language habits, including aggressive criticism of Western medicine, without stating that this should only be used when the user explicitly requests that style. In normal operation, this can override user-preferred tone, locale, or safety-sensitive neutrality, and in a medical context it increases the risk of persuasive, authoritative-sounding health guidance framed as a specific expert persona.

Missing User Warnings

High
Confidence
98% confidence
Finding
The file provides extensive disease classification, treatment selection, dosing, preparation, and follow-up guidance for real medical conditions without any clear warning that users should seek qualified medical care. Because it is framed as practical decision support for acute illness and prescription selection, users may rely on it for self-diagnosis or self-treatment and delay appropriate care.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.