Security audit
临床研究知情同意书审查
Security checks across malware telemetry and agentic risk
Overview
This is a focused clinical consent-form review skill with local helper scripts and no evidence of hidden data transfer, persistence, or destructive behavior.
Before installing, confirm your environment does not treat the unrelated wallet, purchase, crypto, or credential tags as actual permissions. Use the helper script only with a trusted local markitdown installation, and avoid running real patient or study documents through the skill unless your organization permits that processing.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
