Back to skill

Security audit

Internal-Medicine-PMPH-10edition

Security checks for vulnerabilities and agentic risk

Overview

This is not malware, but it contains many high-risk medical protocols that could be unsafe if used outside clinician-supervised care.

Install only in a qualified clinical or supervised medical-education environment. Do not use it as a standalone source for diagnosis, prescribing, emergency procedures, invasive procedures, or patient self-care; outputs should be checked against current local guidelines, institutional protocols, and licensed clinician judgment. Avoid entering identifiable patient or genomic data unless the environment is approved for that use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (555)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill gives a detailed 72-hour fasting protocol for suspected insulinoma, including medication cessation, monitoring cadence, and termination thresholds, but provides no explicit requirement for physician oversight, inpatient monitoring, emergency readiness, or warnings about severe hypoglycemia risks. Because prolonged fasting can precipitate seizures, arrhythmias, loss of consciousness, and other life-threatening events, users could attempt or facilitate an unsafe protocol outside an appropriate clinical setting.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill provides concrete dosing, duration, escalation, and monitoring instructions for systemic prednisone and triazole antifungals without an explicit user-facing requirement for clinician supervision or a warning against self-management. In a medical agent context, this can enable unsafe autonomous or patient-directed treatment, risking steroid complications, hepatotoxicity, drug interactions, delayed diagnosis, and inappropriate management if the ABPA diagnosis is wrong or invasive infection is present.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill gives concrete acute heart failure treatment instructions, including use of diuretics, vasodilators, inotropes, and timing of shock/respiratory failure correction, without any explicit warning that it is informational support and not a substitute for clinician judgment, local protocols, or emergency escalation. In a high-acuity setting, oversimplified or decontextualized guidance can be acted on inappropriately, creating risk of harmful treatment delays, contraindicated therapy, or incorrect hemodynamic management.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill provides actionable medical treatment guidance, including urate-lowering therapy, IV hydration, urine alkalinization, diuretic use, and dialysis thresholds, but does not clearly warn that it is informational only and must not replace clinician judgment or specialist oversight. In a high-risk oncology/nephrology context, omission of that warning can contribute to unsafe autonomous or under-supervised treatment decisions, dosing errors, or inappropriate application to patients with contraindications.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill provides concrete medication selection, dosing, timing, tapering, and efficacy criteria for acute pancreatitis without any visible warning that it is informational only and must be used under qualified clinician supervision. In a medical agent context, users or downstream systems could present these instructions as actionable treatment guidance, creating a real risk of inappropriate therapy, delayed definitive care, dosing errors, or harm in patients with contraindications or atypical presentations.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill gives step-by-step instructions for gastric lavage, an invasive and time-sensitive procedure with substantial risks including aspiration, perforation, hypoxia, and worsening injury if the poisoning context is misidentified. Although framed as a clinical protocol, it lacks explicit user-facing restrictions such as 'for licensed clinicians only,' emergency referral guidance, airway protection requirements, and warnings not to attempt the procedure outside a properly equipped medical setting, making unsafe misuse more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill gives procedural instructions for invasive right-heart-catheter-based vasoreactivity testing and administration of potent vasoactive agents, including titration details and treatment branching, but lacks an explicit high-risk warning that it must only be performed by qualified clinicians in an emergency-capable monitored setting. In an agent context, this can over-encourage operational use as a checklist and may contribute to unsafe application, especially because complications like hypotension, arrhythmia, and decompensation are foreseeable.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill gives concrete emergency-treatment instructions, including IV hydrocortisone dosing, rapid IV fluids, glucose administration, and advising patients to double steroids during stress, but it does not clearly state that these actions require urgent professional medical care and are not appropriate for unsupervised self-management. In a consumer-facing agent context, users may delay emergency services or attempt medication administration without clinical oversight, creating a significant risk of harm or death.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill provides actionable diagnostic triage and urges immediate emergency intervention for suspected MAS/AOSD without any explicit limitation-of-use warning, clinician-only framing, or escalation disclaimer. In a medical agent context, this can cause users to over-trust the output as definitive guidance, potentially delaying proper emergency evaluation or prompting unsafe self-management in a high-risk condition with sepsis-like presentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs ingestion and processing of highly sensitive medical data, including patient histories, imaging, and genomic information, but provides no concrete privacy, consent, minimization, retention, or transmission safeguards. In a clinical context, this omission can lead to unauthorized disclosure of protected health information and genetic data, especially if users treat the skill text as operational guidance for real workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This skill gives directive dosing and escalation guidance for high-risk therapies including high-dose glucocorticoids, cyclophosphamide, rituximab, methylprednisolone pulse therapy, and plasma exchange, but it lacks a prominent user-facing warning that such treatment requires specialist oversight, confirmation of diagnosis, contraindication screening, and monitoring. In a clinical agent context, this can lead to unsafe autonomous recommendations, inappropriate use in undifferentiated patients, or omission of essential safety checks such as infection risk, fertility counseling, cytopenia monitoring, and renal-dose adjustments.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file contains precise antiarrhythmic drug dosing, infusion rates, contraindications, and emergency management thresholds for high-risk medications without any explicit warning that this content is for qualified clinician use only. Because antiarrhythmics have narrow safety margins and can cause torsades, conduction block, hypotension, or death if misapplied, omission of strong gating and safety context creates a realistic risk of unsafe self-treatment or use by insufficiently trained users.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill provides concrete medication names, doses, escalation schedules, and treatment sequencing for aplastic anemia, a safety-critical condition, without an explicit warning that it must not replace clinician judgment or specialist supervision. In an agent setting, such instructions could be surfaced directly to users and acted on without appropriate diagnostic confirmation, contraindication review, monitoring, or individualized dosing adjustments, creating a substantial risk of patient harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This skill gives actionable acute asthma treatment instructions, including corticosteroids, aminophylline dosing, oxygen therapy, acid-base correction, and mechanical ventilation escalation, without an explicit warning that it is for qualified clinician use only and not for self-treatment. In an agent setting, this creates a real risk that unqualified users or downstream systems could act on high-risk medical guidance without adequate safeguards, causing serious injury or delayed emergency care.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill provides ECG-based diagnostic classification and explicitly states the output is used to guide clinical treatment decisions, but it does not warn that it is only an aid and not a substitute for clinician judgment or urgent specialist evaluation. In a medical context, misclassification of AV block severity or block location could delay pacing, misdirect therapy, or create patient safety harm, especially for Mobitz II, high-grade, or complete heart block.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill gives step-by-step CPR instructions for adults, children, and infants in an emergency, safety-critical context but does not explicitly instruct the user to call emergency services, seek trained help, or clarify that CPR should be performed only when indicated. In a real cardiac arrest scenario, omission of escalation guidance can delay definitive care and increase the risk of harm from misuse, especially by untrained users or if the situation is misidentified.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill provides step-by-step medical testing instructions, specimen timing, dosing, and interpretation criteria without clearly warning that the procedure must be ordered, performed, and interpreted by qualified clinicians under appropriate supervision. In a medical context, omission of this guardrail can encourage self-testing or unsupervised use, leading to misinterpretation, delayed diagnosis, unsafe glucose administration, or inappropriate treatment decisions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill gives step-by-step defibrillation instructions for a life-threatening emergency but does not clearly state that defibrillation is a high-risk procedure requiring trained responders, immediate activation of emergency medical services, and use within recognized resuscitation protocols. In a general-purpose agent context, this omission could encourage untrained users to attempt hazardous interventions or delay calling for emergency help, increasing the risk of death or serious harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill provides detailed diagnostic criteria and differential diagnosis steps for a clinical condition without any explicit warning that it is decision-support only and not a substitute for qualified medical judgment. In a healthcare context, omission of such guardrails can encourage overreliance by non-experts or unsupervised use, increasing the risk of misdiagnosis, delayed recognition of organic disease, and patient harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill gives concrete oncology treatment-trigger criteria and names specific anti-cancer regimens and targeted agents, but it does not include an explicit safety warning that this is high-risk medical decision support requiring hematology/oncology specialist review. In the context of CLL, treatment initiation and drug selection depend on nuanced staging, comorbidities, tumor lysis risk, infection status, cytogenetics, and up-to-date guidelines, so omission of guardrails could lead users to act on incomplete or outdated advice with serious patient harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill provides specific high-risk oncology treatment directions, including TKI dose escalation, chemotherapy combination, transplant timing, post-transplant TKI maintenance, and DLI use, but does not include explicit safety boundaries, clinician-only restrictions, or instructions to defer to hematology/HSCT specialists and current institutional protocols. In an agent setting, this creates a real risk that users receive actionable treatment recommendations without appropriate context, contraindication review, or monitoring requirements, which could contribute to severe harm or death.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill gives actionable instructions for clinician-only, safety-critical medical interventions, including provocative testing with acetylcholine/ergonovine and initiation of anti-anginal drugs, without an explicit warning that these require licensed medical supervision and setting-specific safeguards. In a general-purpose agent context, this creates a real risk that non-clinicians or inadequately supervised users could attempt hazardous diagnostic or treatment steps, leading to arrhythmia, infarction, hypotension, or delayed emergency care.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill provides actionable dosing and escalation guidance for corticosteroids, immunosuppressants, biologics, JAK inhibitors, and antibiotics without an explicit warning that these are high-risk prescription therapies requiring clinician oversight, screening, and monitoring. If surfaced directly to end users, it could enable unsafe self-medication or inappropriate clinical use, leading to serious harms such as infection, marrow suppression, TB reactivation, hepatotoxicity, or delayed proper care.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill gives actionable anticoagulation, thrombolysis, thrombectomy, stenting, and IVC filter guidance without explicit safety guardrails about bleeding risk, contraindications, required diagnostic confirmation, or urgent physician supervision. In a clinical assistant context, this could encourage unsafe self-management or overconfident non-specialist use, leading to major hemorrhage, procedural harm, or delayed escalation.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill provides concrete DKA treatment steps including fluid resuscitation, IV insulin infusion, potassium replacement, and monitoring intervals without an explicit warning that this guidance is only for qualified clinicians in a monitored medical setting. Because DKA management is high-risk and errors in insulin, fluids, or potassium can cause arrhythmia, cerebral edema, hypoglycemia, or death, omission of a strong scope-of-use warning materially increases the chance of unsafe use by non-specialists or self-treating users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.