Back to skill

Security audit

Pharma Doc Reference

Security checks across malware telemetry and agentic risk

Overview

This pharma reference skill is mostly documentation, but it tells the agent to automatically install and load another skill without a clear user approval step.

Review and install Universal Task OS separately before using this skill for document generation. Treat this package as read-only reference material unless dependency installation is changed to require explicit user approval, and only add enterprise templates after removing patient information, product secrets, and commercial confidential data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill claims to be a passive reference repository, yet its dependency section instructs activation-time checking, installation, and loading of another skill. This creates hidden execution and supply-chain behavior inconsistent with the declared purpose, increasing the risk of unexpected code paths and trust expansion during activation.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
A document reference library should not unilaterally install another skill, because that expands capabilities and trust boundaries without necessity. Even if the dependency is legitimate, automatic installation introduces supply-chain and privilege-escalation risk if the dependency is replaced, misconfigured, or more capable than expected.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list is extremely broad and includes many common pharma and business terms, making accidental activation likely in ordinary conversations. Over-broad activation increases the chance this skill runs in contexts where it is not intended, which is more dangerous here because the skill also describes dependency-loading behavior.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The documentation describes automatic installation of another skill on activation without any user-facing warning, consent, or confirmation step. Silent dependency changes are dangerous because they can surprise users, bypass administrative review, and mask security-relevant state changes.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.