Back to skill

Security audit

03 Milestone Tracker

Security checks for vulnerabilities and agentic risk

Overview

This skill is a static infant milestone guide with no code or data access, but its developmental assessments should not replace pediatric care.

Install only if you want a Chinese-language educational milestone checklist. For any suspected delay, regression, urgent symptom, prematurity concern, or parental worry, use this as preparation for a pediatric visit rather than as a diagnosis or reason to delay professional care.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill provides infant developmental assessment, warning signals, and care recommendations that users may interpret as medical guidance, yet it lacks a clear disclaimer that it is not a substitute for professional pediatric evaluation. In this context, false reassurance or delayed care for developmental delay could cause real harm, especially because the skill includes specific 'need to seek care' style thresholds that appear authoritative.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description fixes the interaction language to Chinese without stating that language is optional or user-selectable. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.