Back to skill

Security audit

Chinese Medicine 10edition

Security checks across malware telemetry and agentic risk

Overview

This is a coherent TCM reference skill with no malware-like behavior, but it contains actionable medical treatment and procedure guidance that is not consistently scoped to qualified clinical use.

Review before installing. Treat this as educational or clinician-review reference only, not as a tool for self-diagnosis, self-treatment, prescribing herbs, performing acupuncture, or managing cancer, pregnancy, bleeding, eye symptoms, infections, severe pain, dehydration, neurologic symptoms, or emergencies. Use only with a qualified medical or TCM professional and current local clinical guidance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (86)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill content materially conflicts with the surrounding skill metadata: instead of a TCM clinical knowledge base with 172 core skills, the file contains policy-style principles for revising undergraduate clinical medicine textbooks. This kind of scope and identity mismatch can mislead users, routing, and downstream agents into applying the wrong skill in medical contexts, which is especially risky in a healthcare-adjacent system.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README gives concrete examples of syndrome differentiation, formula recommendation, and acupuncture point selection in a way that can be directly operationalized, but the examples themselves do not consistently repeat safety boundaries such as 'not for self-treatment', emergency escalation, pregnancy/procedure cautions, or clinician review requirements. In a medical skill—especially one covering diagnosis, herbs, acupuncture, and other procedural content—users may copy the example pattern and treat generated output as actionable care advice, increasing risk of delayed proper treatment, unsafe self-medication, or harmful self-procedures.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest skill key `tcm` is very broad and likely to match many unrelated prompts that merely mention traditional Chinese medicine. In a medical skill, over-broad activation is riskier than usual because it can inject clinical-style guidance into conversations without clear user intent, increasing the chance of unsafe or unreviewed medical suggestions.

Vague Triggers

Low
Confidence
84% confidence
Finding
The file says each skill includes 'When to Use' trigger conditions, but this manifest does not actually define concrete triggers or exclusions. Without explicit activation boundaries, orchestration systems may invoke the skill in ambiguous health-related contexts, which is especially concerning given the content includes diagnosis, formulas, acupuncture, and other clinical procedures.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This skill provides individualized acupuncture treatment-planning guidance, including point-selection logic and contraindication examples, but does not clearly warn that the output is educational information rather than professional medical advice. In a medical context, omission of that boundary can cause users to rely on the skill for real-world care decisions, increasing the risk of unsafe self-treatment, missed diagnosis, or inappropriate needling.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file gives specific acupuncture point selections for conditions such as stomach pain, facial paralysis, tinnitus, asthma, and pediatric disorders, but does not prominently warn that acupuncture can cause harm if self-administered or performed by unqualified users. Although some contraindications are listed, they are incomplete and could create a false sense of safety, increasing the risk of injury, delayed medical care, or unsafe treatment decisions.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The activation description is overly broad for a medical treatment skill: it triggers on common symptoms like perianal redness, swelling, pain, and optional fever without clear exclusion criteria, triage boundaries, or requirement for clinician oversight. In this context, broad invocation can cause the agent to provide condition-specific treatment and surgical guidance for a potentially serious infection that may require urgent in-person evaluation, increasing risk of misapplication and delayed care.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger condition is phrased as a blanket rule for any T2–T12 back-shu needling scenario, without clearly limiting use to trained clinicians, excluding atypical anatomy, or requiring individualized assessment. In a medical procedural skill, overbroad mandatory guidance can cause unsafe application outside the intended clinical context and suppress case-specific safety judgment.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill explicitly instructs the agent to output an individualized treatment plan, formula recommendation, and drug composition, but provides no safety boundaries, contraindication checks, clinician-only restriction, or advice to seek licensed medical care. In a medical context, this can lead to unsafe or inappropriate treatment recommendations, delayed conventional care, and harm from unsupervised herbal or acupuncture guidance.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The metadata description says the skill should activate when users report broad pain-related symptoms plus tongue/pulse details, which is still expansive for a medical-treatment skill. This can cause the agent to invoke the skill for undifferentiated musculoskeletal complaints and produce treatment-oriented TCM recommendations without adequate triage, diagnostic boundaries, or referral logic.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The 'When to Use' section is broad enough to match common joint or muscle pain presentations, while only minimally excluding acute infectious arthritis and non-Bi pain. In a health context, overbroad triggering increases the chance that users with conditions needing conventional urgent evaluation receive syndrome differentiation and treatment suggestions instead of safer triage guidance.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill provides concrete treatment recommendations, named formulas, and adjunct external therapies without a clear medical safety warning, dosing safeguards, contraindications, or requirement for qualified supervision. In particular, recommending therapies such as herbal formulas and external treatments for painful inflammatory conditions can mislead users into self-management, delay diagnosis, or expose them to adverse effects and interactions.

Missing User Warnings

High
Confidence
98% confidence
Finding
This skill gives syndrome differentiation and specific herbal/formula recommendations for patients with late-stage malignant ascites, a high-risk oncology condition requiring specialist and often urgent conventional management. Although it includes some scope limits, it does not clearly warn end users that the content is not a substitute for oncology care, that ascites may signal clinical deterioration, or that treatment decisions must be made by qualified clinicians because delay or misuse could cause serious harm.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The description says the skill 'must' be used whenever performing TCM pulse diagnosis, creating an unconditional routing rule with no exclusions, safety checks, or clinician discretion. In a clinical skill, this can cause over-application, suppress context-specific judgment, and increase the chance that the agent invokes the protocol in inappropriate or incomplete scenarios.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger condition '所有接受脉诊的患者' is overly broad and ambiguous because it does not specify who is invoking the skill, for what purpose, or under what safeguards. Ambiguous broad triggers are risky in medical contexts because they can cause automatic use outside intended boundaries, including low-context, non-clinical, or edge-case interactions.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill gives condition-identification and treatment recommendations for a menstrual disorder, including differential diagnosis and named formula-based interventions, but does not warn users to seek qualified medical evaluation or state that it is not a substitute for professional care. In this context, delayed menstruation can have non-benign causes such as pregnancy, endocrine disorders, or other gynecologic disease, so omission of referral/safety guidance could lead to harmful self-management and delayed diagnosis.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This skill provides differential diagnosis and specific herbal treatment selection for diarrhea while placing the urgent-care limitation only in a late note. In a medical triage context, delayed safety messaging can cause users or downstream agents to act on treatment advice before recognizing red flags such as dehydration, infection, or other dangerous causes of diarrhea.

Missing User Warnings

High
Confidence
93% confidence
Finding
This skill provides differential diagnosis and treatment guidance for eye conditions, including selecting syndrome types and recommending treatment principles and formulas, but it does not clearly warn that the content is not a substitute for licensed medical evaluation. In an eye-care context, omission of escalation guidance is dangerous because users may self-manage conditions that resemble dry eye but actually require urgent ophthalmic assessment, risking delayed diagnosis and harm to vision.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
This skill provides condition-to-treatment selection guidance for acupuncture or massage without a clear user-facing warning that it is not a substitute for licensed medical evaluation. Because it discusses symptoms such as altered consciousness, febrile illness, stroke-related states, and abdominal or gynecologic conditions, users could rely on the content instead of seeking urgent or appropriate care, increasing the risk of delayed diagnosis or harmful self-treatment.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill gives condition-specific treatment recommendations, including named formulas and escalation guidance, without clearly warning users to seek qualified medical evaluation or stating that the content is not a substitute for professional care. In a gynecology context, early menstruation can overlap with pregnancy-related bleeding, endocrine disorders, fibroids, coagulation issues, or other conditions that require proper diagnosis, so omission of a clinical-safety disclaimer increases the risk of harmful self-management and delayed care.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation criteria are broad enough that an agent could invoke this skill for serious oncology situations without clear boundaries, escalation rules, or requirements for clinician confirmation. In a cancer-treatment context, ambiguous triggering can lead to unsafe or inappropriate recommendations for external herbal interventions, including use of toxic substances, delay of standard care, or application to unsuitable patients.

Missing User Warnings

High
Confidence
95% confidence
Finding
The file gives specific external oncology formulations that include highly toxic substances such as arsenic compounds (信石/红砒, As2O3), mercury-containing preparations (轻粉), and caustic applications for cancer lesions, but it does not clearly warn users not to self-administer or require qualified oncology/TCM supervision. In a knowledge skill about clinical practice, this omission is dangerous because users may treat the content as actionable guidance and attempt unsafe topical cancer treatments, risking poisoning, tissue injury, and delayed evidence-based care.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill provides step-by-step invasive acupuncture manipulation techniques, including needle insertion/withdrawal timing and reinforcing/reducing methods, but omits essential clinical safety guidance such as contraindications, sterile technique, anatomical danger zones, adverse event handling, and the requirement for trained licensed practitioners. Because this is a procedural medical skill involving skin penetration, omission of safety controls could enable unsafe real-world use and lead to injury, infection, pneumothorax, bleeding, or delayed medical care.

Missing User Warnings

High
Confidence
98% confidence
Finding
This skill provides concrete medical decision guidance and treatment principles for clinical conditions, including therapy selection directions for herbal prescriptions or acupuncture, without any user-facing safety warning, limitation statement, or instruction to seek qualified medical care. In a medical context, omission of such safeguards can cause users to rely on the content for self-treatment or inappropriate treatment selection, especially because the skill explicitly frames when and how to apply the treatment logic.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This file gives concrete treatment principles, symptom-pattern mappings, representative formulas, and exclusion criteria in a medical domain, but it does not clearly warn readers that the material is reference-only and not a substitute for qualified diagnosis or urgent medical care. In a user-facing agent skill, that omission can encourage self-diagnosis or delayed escalation of serious symptoms, especially because the content appears authoritative and includes actionable interventions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.