Back to skill

Security audit

Medical Cell Biology-PMPH-7edition

Security checks for vulnerabilities and agentic risk

Overview

This textbook-style medical cell biology skill set includes step-by-step cloning, wet-lab, and cancer-treatment guidance that needs review before use.

Install only if you want an educational/research reference and can enforce your own medical, biosafety, legal, and institutional review boundaries. Do not use it as standalone clinical advice or as a protocol source for embryo work, cloning, hazardous chemistry, radioactive assays, or cell-culture engineering.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (181)

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

This section gives actionable steps for therapeutic and reproductive cloning, including embryo culture to blastocyst, embryonic stem-cell derivation, and implantation into a surrogate. Such operational guidance can facilitate highly regulated and potentially unlawful cloning activity, and the medical-textbook context does not justify providing execution-ready instructions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly recommends cell immortalization methods such as radiation exposure, chemical carcinogen treatment, and oncogene transfection, but provides no safety framing, access controls, or restriction to qualified biosafety contexts. These are hazardous wet-lab interventions that can enable creation or propagation of transformed cell lines, so presenting them as straightforward options materially lowers the barrier to unsafe experimentation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

A skill described as executing somatic cell nuclear transfer and reprogramming for cloning or pluripotent stem cell generation materially exceeds a passive educational catalog and moves into actionable wet-lab bioengineering guidance. In this context, the medical education framing makes it more concerning, because advanced experimental procedures with ethical, biosafety, and regulatory implications are embedded in a broad learning package without visible access controls, safeguards, or restrictions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill provides step-by-step instructions for a hazardous wet-lab setup involving flammable gases (CH₄, H₂), toxic/corrosive ammonia, vacuum operations, boiling liquids, and a 60 kV spark discharge, but includes no safety warnings, qualification requirements, PPE guidance, ventilation requirements, or supervision constraints. In a general-purpose agent skill, this omission materially increases the risk that an unqualified user could attempt the procedure and cause fire, explosion, electric shock, glass implosion, or inhalation injury.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill goes beyond educational cell-biology content and provides an operational SCNT workflow culminating in reproductive cloning for nonhuman use. Even with a narrow disclaimer against human reproductive cloning, the instructions meaningfully enable embryo manipulation and cloning procedures that are highly sensitive, dual-use, and misaligned with the stated textbook-style educational purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill describes creation of patient-specific embryonic stem cells and cloning workflows with only a limited prohibition on human reproductive cloning, but without robust warnings about embryo research restrictions, biosafety controls, consent, animal welfare, and jurisdiction-dependent illegality. That omission increases the risk that users interpret the content as acceptable operational guidance rather than tightly restricted subject matter.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill gives concrete treatment-selection and drug-use guidance for high-risk oncology care, including named agents and implied administration, without any safety disclaimer, clinician-only restriction, emergency warning, or instruction to defer to current specialist protocols. Because cancer therapy decisions are life-critical and highly patient-specific, a user could over-trust this content and apply incomplete or outdated recommendations, causing serious harm.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The line claiming users can 'just input one question' and automatically get a solution from the textbook overstates the invocation scope and encourages use for arbitrary prompts without clear boundaries. In an agent setting, overly broad triggering can cause the skill to activate outside its intended educational domain, increasing the chance of unsafe medical-style guidance or low-relevance responses being presented with undue authority.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger description is broad enough to match many drug transport, metabolism, and chemotherapy-resistance discussions without clear activation boundaries. This can cause the skill to be invoked in contexts where it is only partially relevant, increasing the chance of misleading analysis or overconfident medical guidance, though it does not directly create code-execution or prompt-injection risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file contains user-facing natural-language instructions entirely in Chinese, including the name, description, trigger conditions, and usage notes. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file forces a specific language for the skill’s description and operating instructions, which can violate language/locale policy when no user opt-in or alternative is provided. There is no indication that this skill is region-specific or that Chinese is required for compliance or domain reasons.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file presents the skill name, description, and usage instructions exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown skill enforces a specific language/locale for its name, description, and usage guidance. Under the policy, forcing a language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill name, description, headings, and output text are entirely in Chinese, which effectively imposes a specific language/locale on users. The file does not indicate that Chinese is optional, user-selected, or required for a region-specific purpose, so this is a natural-language policy issue under the locale-choice rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file forces a specific language/locale in its natural-language interface: both the manifest description and all user-facing guidance are exclusively in Chinese. Under the policy, language constraints should not be imposed unless the skill offers user choice or clearly documents a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest name, description, headings, and procedural content are entirely written in Chinese, which imposes a specific language on users without any stated opt-in or alternative. Under the policy, language constraints should either be optional for the user or clearly documented as necessary for a region- or locale-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill name, description, and operating instructions are entirely in Chinese, with no indication that language selection is optional or that the skill is intentionally limited to Chinese-speaking users. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s name, description, usage guidance, and procedural steps are all presented only in Chinese. Under the policy for natural-language violations, forcing a specific language without user opt-in should be flagged unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.