Back to skill

Security audit

Histology and Embryology-PMPH-10edition

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent medical education skill pack, but several included skills give specific diagnosis, procedure, or treatment guidance without consistent clinician-supervision limits at the skill level.

Review this before installing if the agent may answer real patient questions. Treat it as educational reference material only, and require clinician or specialist review for diagnosis, prenatal screening, surgery, transplant, oncology treatment, or medication decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (136)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This skill provides procedural guidance about invasive prenatal diagnostics and intrauterine interventions, including timing windows, without any explicit warning that these actions require qualified obstetric/fetal-medicine supervision and individualized clinical judgment. In a high-stakes medical context, omission of safety boundaries can lead users to overtrust the skill, potentially causing harmful delay, inappropriate self-advocacy, or unsafe decision-making around procedures with maternal-fetal risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

文档把技能描述成知识支持工具,但此处声称可‘执行抗原清除和特异性免疫应答’,属于把生物学过程表述为代理可执行动作的危险拟人化/能力夸大。这会误导用户相信系统能够实施现实世界医疗或生物干预,削弱对其仅能提供信息分析的正确认知。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill gives treatment-oriented guidance for diagnosing limbal stem cell deficiency and recommending or carrying out limbal stem cell transplantation, but it does not clearly warn that the content is educational and not a substitute for licensed ophthalmologic judgment. In a medical context involving severe ocular surface disease and surgery, omission of such guardrails can enable unsafe self-diagnosis, overconfident use by non-specialists, or inappropriate clinical decision support.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill gives treatment-oriented guidance about when PD-1/PD-L1 inhibitors may be considered, but it does not clearly warn that immunotherapy selection requires licensed oncologist review, formal pathology interpretation, and assessment of contraindications and toxicities. In a medical context, omission of such guardrails can lead users to overtrust the skill and make unsafe care decisions, including inappropriate use of immune checkpoint inhibitors with potentially severe adverse effects.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 207)May include surrounding context.

md
<a href="https://www.star-history.com/#xllgreen/Histology-Embryology-PMPH-10edition&Date">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date" />
 </picture>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 208)May include surrounding context.

md
<a href="https://www.star-history.com/#xllgreen/Histology-Embryology-PMPH-10edition&Date">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date" />
 </picture>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 209)May include surrounding context.

md
<a href="https://www.star-history.com/#xllgreen/Histology-Embryology-PMPH-10edition&Date">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date" />
 </picture>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README_EN.md (reported line 134)May include surrounding context.

md
<a href="https://www.star-history.com/#xllgreen/Histology-Embryology-PMPH-10edition&Date">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date" />
 </picture>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README_EN.md (reported line 135)May include surrounding context.

md
<a href="https://www.star-history.com/#xllgreen/Histology-Embryology-PMPH-10edition&Date">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date" />
 </picture>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README_EN.md (reported line 136)May include surrounding context.

md
<a href="https://www.star-history.com/#xllgreen/Histology-Embryology-PMPH-10edition&Date">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=xllgreen/Histology-Embryology-PMPH-10edition&type=Date" />
 </picture>

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file states '通过自然语言提问调用具体技能' without giving specific trigger phrases, scope limitations, or examples of what should not activate the skill pack. That makes activation semantics ambiguous and could overlap with ordinary conversation, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill name, description, triggers, instructions, and output requirements are entirely written in Chinese, with no indication that the user can choose another language. Under the policy for natural-language violations, this is a locale/language constraint that is not presented as optional or justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire skill is written in Chinese and provides no indication that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific workflow. Under the policy for natural-language violations, forcing a specific language without user opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file forces a specific language for all user-facing content, which can violate language/locale policy when no user opt-in or alternative is provided. There is no indication that the skill is region-specific or that Chinese is required for compliance or audience constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file forces a specific language for the skill name, description, and operating instructions, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language context. This matches the language/locale policy violation category for natural-language policy issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill name, description, and all instructional content are written entirely in Chinese, with no indication that the user can choose another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file is entirely written as a Chinese-language skill and does not indicate that the user may choose another language or that the language restriction is region-specific. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger condition is framed as domain-state logic ('when embryonic development enters week 7') rather than a clear user-intent boundary, which can cause the agent to invoke the skill inappropriately whenever related content appears. This is not directly exploitable as code execution or prompt injection, but it can lead to unreliable routing, over-broad activation, and incorrect responses in adjacent neuroscience or pathology contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly requires adherence to a specific political/ideological framework as a mandatory condition of use, without user choice, contextual gating, or locale-specific justification inside the skill itself. In an agent setting, this can bias outputs, reduce neutrality, and cause the system to privilege ideological compliance over user intent or evidence-based educational assistance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language description and operating instructions are entirely in Chinese, with no indication that the user can choose another language or that the skill is intentionally restricted to a Chinese-language audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill name, description, headings, and output guidance are entirely in Chinese, which imposes a language choice on the user without any opt-in or alternative. Under the policy, language-specific behavior should either offer a choice or clearly document a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill name, description, and all operating instructions are written entirely in Chinese, with no indication that users may interact in another language or that the skill is intentionally restricted to a Chinese-speaking or region-specific context. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.