Back to skill

Security audit

健康管理器

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a health assistant, but it mixes in unrelated automation and command-execution claims while under-disclosing privacy and medical-advice risks.

Review this skill carefully before installing. It may ask an agent to handle sensitive health and medication details, but it does not clearly explain privacy, retention, deletion, or clinician-review boundaries, and it declares broad read/write/exec capabilities beyond the health use case.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill is presented as a personal health assistant, but later sections advertise generic file parsing, API aggregation, and command execution performance characteristics that are unrelated to health workflows. This mismatch increases the risk that users or an agent will grant broader trust and permissions than necessary, especially because the declared tools include exec and write, creating a misleading capability boundary.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The description mixes personal health management with unrelated project management, task planning, progress tracking, and team collaboration language. In a security-sensitive skill manifest, this kind of cross-domain confusion is dangerous because it obscures the real purpose of the skill and can conceal overly broad or unintended behavior behind a benign health-themed label.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation guidance is ambiguous and spans unrelated use cases, making it unclear when the skill should be activated. Ambiguous activation criteria can cause an agent to invoke a powerful skill in the wrong context, particularly one that advertises read/exec/write tools, increasing the chance of overreach or misuse.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill is designed to process highly sensitive health and medication information, but the manifest area does not provide a clear, user-facing privacy warning or data-handling notice. In the context of personal health data, missing privacy disclosures increase the risk of users sharing protected information without understanding storage, transmission, retention, or access implications.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill provides medication lists, interaction warnings, symptom analysis, exercise guidance, and red-flag triage content without a prominent disclaimer that output is informational and not professional medical advice. In a health context, users may rely on the tool for diagnosis, treatment, or medication decisions, which can lead to delayed care, contraindicated actions, or harmful self-management.

Static analysis

No suspicious patterns detected.