Back to skill

Security audit

Hybrid MD Assistant.

Security checks for vulnerabilities and agentic risk

Overview

This skill is only a markdown persona prompt, but it broadly redirects the agent to impersonate a named medical/investment persona and make every response serve that brand or trading project.

Install only if you specifically want a narrowly scoped persona for this bootcamp/brand project. Before use, remove or revise the named-person impersonation, the medical/investment authority claims, and the instruction that every response must support the bootcamp or trading wing; add clear medical and financial disclaimers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
skill.md:1
Finding

Agent Identity and Objective Hijacking Through Skill Instructions

Content
View full analysis

Vulnerability Details

File Location: skill.md, lines 1–29
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Skill Content:

markdown
# Agent Identity: The Hybrid MD (Dr. Mohamed)

## Profile

You are the digital twin of Dr. Mohamed Kassab. You are a unique hybrid of:

- **Medical Expert:** Physician & Medical Insurance Approval Supervisor.
- **Tech Expert:** Python & SQL Developer.
- **Investor:** Sharia-compliant Trading (Binance/Forex).

## Core Mission

Your primary goal is to manage and execute "The Hybrid MD Bootcamp", an educational program designed to bridge the gap between Medicine and Technology.

## Current Tasks

1. **Bootcamp Structuring:** Help organize the 1st lecture titled "The Digital Physician: Transitioning from Clinic to Code".
1. **LinkedIn Strategy:** Draft authoritative posts about the intersection of Health-Tech to build the "Hybrid MD" brand.
1. **Trading Analysis:** Provide data-driven insights for Forex/Binance using Python logic, ensuring all suggestions align with Sharia-compliant principles.

## Tone and Style

- Professional, authoritative, yet encouraging for fellow doctors.
- Efficient and code-oriented when discussing tech.
- Strategic and calculated when discussing investments.

## Interaction Protocol

Always remember that you are building an "Empire". Every response should contribute to the Bootcamp's growth or the precision of the trading wing.

Technical Analysis

The Skill does not merely provide optional domain context. It directly assigns the Agent a new identity by declaring it to be the “digital twin” of a named individual, replaces its primary objective with management of that individual's bootcamp, and imposes a universal instruction that every response must advance the bootcamp or trading operation.

The phrases “Your primary goal” and “Every response should contribute” create broad, sessio ...[truncated 2359 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction assigning the Agent the identity of a named individual. Describe the Skill as an assistant for a project or subject area rather than as a person's “digital twin.”
  2. Replace “Your primary goal” with a narrowly scoped capability statement that applies only when the user explicitly requests bootcamp, health-technology writing, or trading-analysis assistance.
  3. Delete the requirement that “Every response” advance the bootcamp or trading wing. The Skill must not affect unrelated tasks.
  4. Add an explicit instruction that the Agent must not claim to be, speak on behalf of, or possess the credentials of Dr. Mohamed Kassab or any other real person.
  5. Require clear disclosure that generated medical and financial material is informational and does not constitute professional diagnosis, treatment, insurance authorization, or personalized investment advice.
  6. Preserve the host Agent's existing safety rules, user-selected goals, and instruction hierarchy by stating that Skill guidance is subordinate to platform policies and the user's current request.
  7. Constrain each capability to explicit invocation and relevant context so branding, promotional, medical, and trading objectives cannot leak into unrelated responses.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 1)May include surrounding context.

md
\# Agent Identity: The Hybrid MD (Dr. Mohamed)

\## Profile

Static analysis

No suspicious patterns detected.