Back to skill

Security audit

quanmi-fiber-pipeline

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed diabetes product and marketing pipeline, but it asks agents to automate sensitive glucose monitoring, health advice, evidence packaging, and sales follow-up without enough consent, privacy, and clinical guardrails.

Install only if you intend to use a Chinese-language, commercially oriented diabetes-product workflow and can supply your own medical, legal, privacy, and compliance review. Do not use it to process identifiable patient data, send sales outreach, publish evidence packages, or provide individualized diabetes advice unless consent, clinician oversight, data minimization, retention, access controls, opt-out handling, and jurisdiction-specific health-data compliance are already in place.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The file’s own constraint forbids competitor rebuttals from using terms like “骗局”, yet the patient-facing example includes exactly that word. In a regulated health-marketing workflow, this contradiction can cause downstream generation or review systems to emit defamatory or non-compliant sales copy, increasing legal and platform-enforcement risk.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The skill explicitly requires real literature only, but the examples include citations that appear fabricated, future-dated, or internally inconsistent with that rule. In a medical-content pipeline, fabricated references can mislead clinicians, patients, and compliance reviewers, and may be reused as authoritative support for health claims.

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The file broadens a disease-management skill into company-building, channel strategy, pricing, hospital entry, and operational planning that go beyond the declared scope. This increases the chance the agent will perform or recommend business actions unrelated to the user’s request, creating scope creep and unintended high-stakes decision support in regulated healthcare and sales contexts.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The document directs use of a mini-program to activate a very large existing diabetic user base, which implies mass outreach, profiling, and operational targeting of a sensitive health population. In a healthcare context, this is dangerous because it encourages large-scale handling and activation of health-related user segments without any visible consent, authorization, privacy controls, or compliance guardrails.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes very broad phrases such as '糖尿病管理方案' and '糖尿病服务包', which can match many ordinary healthcare or nutrition requests and cause the skill to activate outside its intended scope. In this skill, unintended activation is more concerning because the workflow is designed to auto-initiate a multi-stage commercial-medical pipeline, including content generation, validation, and sales activation, so an accidental match could steer benign user requests into domain-specific medical-marketing behavior.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This section describes continuous collection, automated upload, analysis, and push notifications based on highly sensitive health data, including CGM glucose readings and related health status, but provides no privacy notice, consent flow, retention limits, access controls, or handling restrictions. In a diabetes-management context, this omission is dangerous because the system is explicitly designed to operationalize automated health monitoring and decision support at scale, creating material risk of privacy violations, unauthorized profiling, and misuse of health data.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This flow uses abnormal health-screening results to automatically recommend and convert users into a paid '14-day plan' during a moment of medical vulnerability, without any warning, consent language, or boundary between health assessment and marketing automation. That is risky because it enables profiling and automated targeting based on sensitive medical information, potentially violating privacy expectations and manipulating users in a high-pressure health context.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill specifies continuous CGM data collection, Bluetooth/app relay, cloud API upload, OCR-based manual upload, and storage fields including device and patient identifiers, but does not present an explicit privacy notice, consent requirement, retention policy, or handling safeguards to the end user in this section. In a health context, this creates meaningful risk of unauthorized collection, transmission, or secondary use of sensitive medical data, especially because the workflow is designed for operational reuse by companies.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill includes automated patient-facing recommendations on fiber dosing, meal timing, and exercise triggered by glucose readings, yet lacks an upfront warning that these suggestions are not medical advice and may be unsafe for some patients without clinician review. In a diabetes-management workflow, users may reasonably rely on these outputs as treatment guidance, increasing the chance of harm from inappropriate self-management, delayed care, or misuse during adverse events.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill specifies automatic collection, analysis, anomaly detection, and reporting of patient CGM data, which is sensitive health information, but it does not state any privacy notice, consent requirement, retention limit, access control, or data-handling safeguard. In a diabetes-management workflow, this omission can lead to unauthorized processing or disclosure of medical data and unsafe reliance on automated recommendations without clear governance.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This section operationalizes continuous CGM monitoring, anomaly detection, and automated advice for patients handling sensitive health data, but only mentions privacy in passing as an internal constraint rather than requiring explicit consent, user-facing disclosure, retention limits, access control, or incident handling. In a diabetes-management pipeline, that omission is dangerous because it normalizes large-scale processing of regulated health data and automated health recommendations without clear safeguards, increasing risk of privacy harm, unauthorized disclosure, and unsafe over-reliance on automation.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The sales automation workflow instructs automatic follow-up, sending validation data, and FAQ-driven responses, but does not require recipient consent, opt-out controls, disclosure boundaries, or rules preventing sharing of sensitive or misleading efficacy information. In this skill's context, the risk is elevated because the surrounding system processes health outcomes and B-end evidence packages, so automated outreach could expose sensitive data, facilitate non-compliant marketing, or pressure recipients with medical-result claims.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The file defines all role instructions and activation phrases exclusively in Chinese and does not provide any language selection, fallback, or opt-in mechanism. In practice this can exclude or mislead non-Chinese-speaking users, increase the chance of unsafe misunderstanding in a health-related workflow, and reduce informed user control over how the skill operates.

Missing User Warnings

High
Confidence
98% confidence
Finding
The file makes strong medical claims about treating or reversing diabetes, reducing blood glucose, replacing or avoiding medication escalation, and proving efficacy through anecdotal examples, but provides no warning to seek licensed medical advice or avoid replacing prescribed treatment. In a health-impacting skill, this is dangerous because users may follow unsupported recommendations, delay proper care, or alter medication behavior based on persuasive marketing-style guidance.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill describes continuous collection and automated analysis of highly sensitive health data, including CGM readings, age, disease duration, medication status, and individualized recommendations, but does not define consent, lawful basis, retention, minimization, access control, or patient notice. In a diabetes-management pipeline, this omission is dangerous because the workflow operationalizes medical data processing at scale, making unauthorized collection, over-processing, or misuse of health information much more likely.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill states that validation evidence packages may be used for B-end partnership negotiations and academic publication, but it does not require de-identification, separate consent for secondary use, ethics review, or controls on external disclosure. Because the evidence derives from patient health data in a disease-management context, this creates a high-risk path for privacy breaches, unlawful secondary processing, and re-identification when data is shared outside the original care/validation workflow.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.