Back to skill

Security audit

wujutong

Security checks across malware telemetry and agentic risk

Overview

This is a historical Chinese-medicine reference skill, but it also gives concrete diagnosis, formula, and dosage-style guidance for serious illnesses, so it should be reviewed carefully before use.

Install only if you want a historical/academic TCM reference and can prevent it from being used as medical advice. Do not rely on it for diagnosis, prescriptions, dosages, emergency symptoms, infectious disease, pediatric illness, pregnancy, bleeding, convulsions, or toxic herb use; route real health questions to licensed clinicians.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (36)

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The README states the skill is only for education/research and does not provide diagnosis or treatment, but the documented examples explicitly give case-specific syndrome assessment, named formulas, contraindication logic, and concrete gram dosages. This mismatch is dangerous because users may treat the disclaimer as sufficient safety coverage while still receiving actionable medical instructions that can influence real-world care.

Intent-Code Divergence

Medium
Confidence
99% confidence
Finding
The disclaimer says the skill does not provide prescriptions or individualized treatment advice, yet earlier examples provide individualized prescriptions with herb names, exact dosing, and decision points tied to a specific patient presentation. In a medical context, this can mislead users into relying on the skill for treatment despite the nominal warning, increasing the risk of unsafe self-medication or delayed professional care.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The README’s disclaimer states the skill does not provide diagnosis, prescriptions, or individualized treatment advice, yet earlier sections explicitly present diagnostic reasoning, formula selection, escalation logic, and herb dosages. This mismatch can mislead users into treating the output as safe educational content while still receiving actionable medical instructions, increasing the risk of unsafe self-treatment or delayed real medical care.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The bundled case index materially exceeds the declared scope of a 温病-focused skill by including many non-温病 categories. In a medical guidance context, scope drift is dangerous because retrieval may surface out-of-scope cases and produce advice under an authority framing that users may trust as domain-appropriate when it is not.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
Including a dedicated 伤寒 category directly contradicts the manifest statement that the skill is not applicable to 伤寒/经方派 questions. In a medical skill, this inconsistency can cause the agent to answer excluded-condition questions anyway, leading to misleading or inappropriate treatment suggestions under false scope assurances.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The presence of detailed 伤寒 records makes accidental or intentional retrieval of excluded medical content highly likely, not merely theoretical. Because these are concrete cases rather than labels, they can strongly steer model outputs toward specific out-of-scope diagnoses or remedies, increasing the chance of unsafe medical advice.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill metadata explicitly says it is not applicable to 伤寒/经方派 topics, yet this file is a dedicated 伤寒 case file with diagnostic and treatment content. This creates scope-confusion and can cause the agent to answer excluded medical topics anyway, increasing the risk of unsafe or misleading medical guidance outside the declared operating boundary.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The document explicitly broadens the skill from a Wu Jutong/温病派 corpus into a cross-school formula index, including 伤寒方 and other non-core prescriptions. In a medically themed skill, this creates scope drift between the declared specialization and the actual decision support content, increasing the chance that the agent presents recommendations with unjustified authority or uses formulas outside the user's expected framework.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
These sections instruct the model to consult this table when selecting formulas not in Wu Jutong's 22 core prescriptions and for cross-school mapping, which effectively authorizes non-core therapeutic guidance. Because the skill operates in a health context, this can cause the agent to generate treatment suggestions beyond its declared expertise, raising the risk of unsafe or misleading medical advice.

Context-Inappropriate Capability

Low
Confidence
81% confidence
Finding
The document instructs the system to use a search tool to infer the current season, which expands behavior beyond a static diagnostic reference into external-context collection without clear necessity or constraints. In a medical guidance skill, even a small unjustified tool invocation increases attack surface and can propagate incorrect assumptions into diagnostic branching.

Missing User Warnings

High
Confidence
97% confidence
Finding
The example provides concrete patient-specific prescribing guidance, named formulas, contraindication logic, and exact gram dosages without an immediate, prominent safety warning at the point of use. In a medical skill context, these details materially increase the chance that users will copy the regimen directly, especially because the skill is framed as clinically challengeable and safety-aware.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill provides concrete diagnostic heuristics and named treatment/formula selection for medical conditions, including severe presentations such as high fever, delirium, convulsions, and constipation, while the disclaimer is limited to 'academic research and role-play' and does not strongly interrupt unsafe self-treatment. In practice, users may treat this as actionable medical guidance, especially because the content is structured as decision rules, contraindications, and formula choices, which can delay urgent care or cause harmful self-medication.

Missing User Warnings

High
Confidence
99% confidence
Finding
This section maps modern diseases such as COVID-19, bacterial pneumonia, dysentery, meningitis, tonsillitis, and pediatric febrile seizures to specific traditional formulas, making the content directly actionable despite only limited later caveats about non-equivalence. Users could interpret these mappings as treatment recommendations for serious infectious or neurologic illness, risking delayed diagnosis, inappropriate self-treatment, and harm from potent substances referenced elsewhere in the skill.

Missing User Warnings

High
Confidence
97% confidence
Finding
The file enumerates many diseases, formulas, and medication-like interventions across a medical case index without any visible disclaimer that this is historical/reference content rather than treatment guidance. In a user-facing medical skill, that omission increases the chance that users interpret indexed remedies and pills as actionable advice, which can lead to unsafe self-medication or delayed professional care.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The file presents symptom/disease/formula lookup guidance for medical complaints in a rapid-reference format without any warning that it is educational material and not professional medical advice. In a user-facing agent, this can encourage self-diagnosis or self-treatment for serious conditions such as fever, bleeding, delirium, edema, or psychiatric symptoms, creating a real risk of harmful delay, inappropriate treatment, or unsafe medication use.

Missing User Warnings

High
Confidence
98% confidence
Finding
This file provides detailed disease interpretation and specific treatment recommendations, including named formulas, dosage-like quantities, and statements implying what should or should not be prescribed, but it contains no safety disclaimer, triage guidance, or instruction to seek licensed medical care. In a skill intended to answer users from a named medical master's perspective, this can encourage users to self-diagnose or self-medicate using historical remedies, creating a significant risk of delayed care, toxic exposure, contraindications, or harm to children and medically fragile users.

Missing User Warnings

High
Confidence
97% confidence
Finding
This file contains direct medical case descriptions and treatment formulas for hematemesis, including specific substances, dosages, and implied efficacy, but provides no warning that the material is historical reference content rather than professional medical advice. Because the skill is explicitly framed as an operational system for diagnostic and treatment reasoning, users may act on it for a potentially life-threatening symptom, creating a substantial risk of delayed emergency care, unsafe self-medication, or inappropriate treatment.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The file contains historical medical case records with specific herbal formulas, dosing amounts, indications, and claimed outcomes, but provides no visible disclaimer that this content is for historical/reference purposes only and not medical advice. In a skill explicitly designed to answer users from a clinician-style perspective, users may treat these prescriptions as actionable guidance, creating a real risk of unsafe self-diagnosis, delayed care, inappropriate herbal use, and harmful use in children or medically fragile people.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This file presents historical medical case descriptions and detailed treatment formulas, including named remedies and dosing-style ingredient lists, without any clear warning that the material is historical reference content rather than safe, current medical guidance. In a user-facing skill that may be triggered for symptom-related questions, this creates a meaningful risk that users self-diagnose or self-administer potentially unsafe treatments, especially for urgent conditions such as throat swelling and difficulty swallowing.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This file provides numerous historical medical case records and specific treatment formulas, including named preparations and ingredient dosages, without any disclaimer that the content is historical/educational and not medical advice. In a deployed skill, users may interpret these formulas as actionable guidance for acute illness, including severe presentations such as delirium, convulsions, and pediatric cases, creating a meaningful risk of unsafe self-treatment or delayed professional care.

Missing User Warnings

High
Confidence
98% confidence
Finding
The file contains extensive case-based treatment recommendations, dosages, and named formulas for serious infectious febrile illnesses, but does not warn that this is historical TCM source material rather than safe modern medical guidance. In a skill designed to answer user questions in the voice of a historical physician, users could reasonably treat these instructions as actionable care, creating risk of delayed evidence-based treatment, toxic ingestion, or harmful self-medication.

Missing User Warnings

High
Confidence
98% confidence
Finding
This file contains numerous detailed medical case records, diagnoses, herbal prescriptions, dosing amounts, and references to invasive or dangerous interventions without any safety framing, contraindication warnings, or instruction to seek licensed medical care. Because the skill is explicitly designed to be triggered for users seeking diagnostic and treatment guidance in a traditional medicine context, users could treat this as actionable medical advice and attempt unsafe self-treatment, including use of potent substances or inappropriate care delays.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
This file contains detailed historical medical case content with specific herbal remedies, named formulas, and exact dosages, but does not warn users that the material is historical/educational and not safe for self-diagnosis or self-treatment. That is dangerous because users may interpret the cases as actionable clinical guidance, including use of potent or toxic substances such as附子、川乌头等, leading to poisoning, delayed proper care, or harmful treatment based on incomplete context.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This section presents historical medical treatment guidance involving a highly toxic substance (巴豆) and strong purgative methods without any safety framing, contraindications, dosage-risk warning, or instruction to seek licensed medical care. Even though the content is historical TCM material rather than overtly malicious, users could misinterpret it as actionable self-treatment and suffer poisoning, severe gastrointestinal injury, dehydration, or delayed proper care.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
This passage gives stepwise repeat-dosing instructions for an aggressive purgative regimen using 巴豆霜, including escalation if the first attempts fail, but provides no user-facing warning about toxicity, overdose risk, bowel obstruction danger, or the need for urgent medical supervision. In the context of a skill that may answer users in an authoritative practitioner voice, this creates a substantial risk of harmful imitation, especially for constipation, abdominal masses, or acute abdominal pain where self-treatment could be life-threatening.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.