Back to skill

Security audit

ClinicalKey

Security checks for vulnerabilities and agentic risk

Overview

The skill is read-only and disclosed, but it can access account-level ClinicalKey usage and member data while telling agents to use it for any ClinicalKey request.

Review before installing if the connected ClinicalKey account contains sensitive institutional usage, report, or consortium member data. The skill does not show destructive behavior, but its trigger language is broad enough that an agent may route more ClinicalKey requests through this connector than a user expects.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The manifest and description frame the skill as suitable for any ClinicalKey request involving 'searching and reading data', but the exposed actions include account-level operational and usage-reporting functions that are broader than ordinary content retrieval. This mismatch can cause an agent to invoke the skill in contexts the user did not intend, potentially exposing administrative metadata or institutional usage information.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The phrase 'Use this skill for ANY ClinicalKey request' is overly broad and encourages indiscriminate routing of all ClinicalKey-related tasks through this skill without scope checks. In practice, that can lead an agent to overuse a connector with access to account-level data, increasing the chance of unintended disclosure or misuse of tenant-specific information.

Static analysis

No suspicious patterns detected.