Back to skill

Security audit

天津坤如玛丽妇产医院医疗知识库

Security checks across malware telemetry and agentic risk

Overview

This is a hospital knowledge and marketing-content skill with no executable code, persistence, or data access, though its medical-topic activation rules are broader than ideal.

Install this only where hospital-specific information or promotional material for 天津坤如玛丽妇产医院 is desired. Configure agents to confirm the user is asking about this hospital before using its prices, doctors, packages, or sales templates, and do not rely on it for general medical diagnosis, triage, emergencies, or current pricing without verification.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation rules are broad enough to match generic Tianjin obstetrics, gynecology, pediatrics, fertility, and postpartum queries that may not specifically concern this hospital. This can cause the agent to inappropriately route unrelated medical or marketing requests to a hospital-specific promotional skill, increasing the risk of brand-biased answers, misrouting, and unsafe medical commercialization in contexts where neutral or general medical guidance would be more appropriate.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description states the skill should be used for 'any medical service' related to the hospital and for generating marketing content, but it does not clearly constrain when hospital-specific content is appropriate versus when a user is asking a general medical question. In a medical domain, ambiguous routing is risky because it can steer health-related queries into a sales/promotional workflow and produce overly specific institutional recommendations without adequate scope checks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.