Back to skill

Security audit

Medical Genetics 8edition

Security checks for vulnerabilities and agentic risk

Overview

This is a medical genetics reference skill with no executable code, but it includes direct clinical and gene-therapy procedure guidance that needs stronger professional safeguards.

Review this skill as high-stakes medical decision support. Install only if users understand that outputs must be handled by qualified clinicians or genetics professionals, real patient/genomic data needs privacy and consent controls, and treatment, gene therapy, forensic, reproductive, or prenatal decisions must follow applicable laws, laboratory standards, and specialist review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (160)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill provides operational guidance for forensic DNA identification and paternity testing, both of which involve highly sensitive biometric and familial data, but it omits safeguards around informed consent, legal authority, privacy handling, and evidentiary chain-of-custody. In this context, the omission is dangerous because it can facilitate unauthorized testing, privacy violations, legally invalid conclusions, or misuse in criminal and family disputes.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill gives actionable medical treatment advice to 'immediately start intravenous immunoglobulin replacement therapy' and proceed with diagnostic workup, but it lacks any explicit limitation to licensed clinicians, warning about contraindications, or requirement for specialist evaluation. In an agent setting, this can be presented as direct treatment guidance for a suspected diagnosis, creating a meaningful risk of misdiagnosis, inappropriate therapy initiation, and delayed care for alternative causes of elevated IgM.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill gives step-by-step guidance for selecting and carrying out gene augmentation therapy without clearly warning that this is a highly specialized clinical intervention requiring licensed medical, laboratory, and regulatory oversight. In a medical genetics context, operational instructions for gene transfer into target cells could mislead users into treating the content as actionable procedural advice, increasing the risk of unsafe experimentation or inappropriate clinical decision-making.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill gives operational guidance for genome editing and presents CRISPR/Cas9 as a preferred precise repair method, but it omits critical safety constraints such as off-target mutation risk, on-target large deletions/rearrangements, mosaicism, delivery toxicity, validation requirements, and the need for trained clinical/laboratory oversight. In a medical genetics context, this can over-encourage hazardous real-world use of gene-editing procedures by users who may underestimate the risks, making the omission materially dangerous rather than merely incomplete.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill handles highly sensitive genomic data and produces individualized diagnostic, treatment, and prevention recommendations without any explicit warning about privacy, consent, or the limitations of AI-mediated medical guidance. In this context, missing safeguards can lead to disclosure or misuse of genetic information and overreliance on unreviewed medical recommendations, which is especially dangerous because genomic data is uniquely identifying and has implications for both the patient and relatives.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill provides actionable guidance for designing gene therapy, RNA interference, suicide gene therapy, immune gene delivery, and microRNA-based interventions without any safety boundary, clinician-only limitation, or warning that these are experimental high-risk medical interventions. In a generally accessible agent skill, this can enable unsafe medical advice or operational planning for advanced biologic interventions by unqualified users, increasing risk of patient harm and misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill provides concrete oncology treatment-selection steps, including mutation screening, target validation, drug selection, and treatment initiation, but does not warn that this information is not a substitute for licensed oncologic and molecular-pathology judgment. In a high-risk medical domain such as cancer therapy, omission of that warning can encourage overreliance on the skill for clinical decision-making, potentially leading to inappropriate drug choice, missed contraindications, or misuse outside guideline-supported indications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The document presents the skill primarily in Chinese from the title onward, with English only linked as an alternative later. This can indicate a language policy issue because users are not offered an explicit language choice before the skill description is delivered.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The embedded Star History image loads remote content from api.star-history.com when the README is rendered, causing passive network requests to a third party. While common in GitHub READMEs, this can disclose viewer metadata such as IP address, user agent, and access timing, which is an external transmission concern.

Content

Scanner excerpt · README.md (reported line 207)May include surrounding context.

md
<a href="https://www.star-history.com/#repo&type=date">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=&type=date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=&type=date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=&type=date" />
 </picture>

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

This line continues the same embedded third-party Star History resource pattern and results in outbound requests during README rendering. The risk is limited to metadata leakage and availability dependence on an external service, not code execution.

Content

Scanner excerpt · README.md (reported line 208)May include surrounding context.

md
<a href="https://www.star-history.com/#repo&type=date">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=&type=date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=&type=date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=&type=date" />
 </picture>
</a>

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The picture/source markup references remote SVG content from a third-party API, which can leak access metadata whenever a client renders the README. In the context of a medical genetics skill, this does not directly worsen clinical risk, but it still introduces unnecessary third-party contact from documentation.

Content

Scanner excerpt · README.md (reported line 209)May include surrounding context.

md
<picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=&type=date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=&type=date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=&type=date" />
 </picture>
</a>

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly says it can assist clinical decision-making but does not warn that it is not a substitute for qualified medical judgment. In a medical genetics context, users may over-rely on model output for screening, diagnosis, reproductive counseling, or treatment-related decisions, increasing the risk of harmful or inappropriate care.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill’s name, description, and operating instructions are all presented only in Chinese. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s name, description, and operational instructions all require Chinese comprehension, but there is no indication that users can opt into another language or that the skill is intentionally restricted to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill name, description, and operational instructions are entirely written in Chinese, with no indication that another language is available or that Chinese is a justified locale requirement. This can violate language/locale policy where skills should not force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill recommends genetic testing, interprets AD risk variants, and mentions personalized prevention, but does not warn that genetic results are sensitive health data or that interpretation requires qualified medical/genetic counseling. In this medical context, users could overtrust the output, misunderstand probabilistic risk, or disclose/store sensitive genomic information without appropriate safeguards.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill name, description, headings, and instructions are entirely in Chinese, which imposes a specific language on users without any opt-in or alternative locale noted. The policy for this audit flags language/locale constraints when the skill does not explicitly offer a choice or justify the restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing instructional content only in Chinese, which can constitute a language/locale policy violation when no user opt-in or alternative language option is provided. The file does not indicate that the skill is region-specific or intentionally limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill name, description, triggers, and instructions are entirely in Chinese, with no indication that the user can choose another language or that the language restriction is intentionally limited to a justified locale-specific deployment. This is a natural-language policy issue because the file effectively mandates one language without offering user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest name, description, headings, and procedural text are entirely in Chinese, which effectively imposes a specific language on users. The file does not indicate that other languages are supported or that Chinese is an optional locale, so this is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.