Back to skill

Security audit

Medical Imaging 9th Edition

Security checks for vulnerabilities and agentic risk

Overview

The skill is not technically malicious, but it needs review because it gives high-stakes medical diagnosis and invasive-procedure guidance without consistent safety boundaries.

Treat this as Review rather than malware. Install only for educational/reference use or tightly supervised clinician workflows, not for patient self-care or autonomous clinical operation. Before use with real cases, enforce medical safety policy, qualified clinician review, local protocol checks, current guideline verification, and privacy controls for any patient images or metadata.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (125)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow directs use of AI across scheduling, imaging, post-processing, diagnosis, and reporting but does not warn about privacy, consent, access control, data retention, model governance, or the risks of transmitting patient images and metadata to third-party systems. Because medical imaging data is highly sensitive and often regulated, omission of these safeguards can lead to unauthorized disclosure, improper processing, and unsafe clinical reliance on AI outputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill gives a direct rule to skip lower-tier evaluation and proceed to coronary angiography for acute myocardial infarction, but it does not clearly state that this is a high-risk, specialist-only emergency decision that must be made within formal clinical protocols. In a clinical decision-support context, omission of that warning can cause overreliance by non-specialists or inappropriate use outside the intended setting, creating risk of invasive harm, delay, or mis-triage.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill gives procedural and pre-procedural guidance for carotid artery stenting, including mandatory DSA and embolic protection device use, but does not state that the content is informational only or that CAS candidacy must be determined by qualified specialists under formal clinical guidelines. Because this concerns an invasive, high-risk cerebrovascular intervention, omission of explicit clinical-safety boundaries could cause overreliance by users and unsafe decision support in real patient care.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill provides medical risk stratification and treatment-adjacent guidance about myocardial ischemia and whether intervention may be needed, but it does not clearly warn that the output is not a substitute for clinician evaluation or emergency care. In a cardiology context, users may over-rely on simplified stenosis thresholds and delay urgent treatment for acute coronary syndrome or misunderstand serious symptoms as low risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill provides step-by-step instructions for an invasive vascular access procedure that can cause severe bleeding, arterial injury, dissection, infection, embolic complications, or death if attempted by unqualified users. Although framed as a clinical skill, it lacks explicit warnings that the procedure is high-risk, for trained professionals only, and dependent on sterile technique, patient selection, emergency backup, and institutional safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill gives concrete treatment actions including antiemetic medication, oxygen administration, and analgesic selection without explicitly requiring clinician assessment, dosing verification, contraindication review, or urgent escalation thresholds before treatment. In a medical skill, this can cause unsafe autonomous or semi-autonomous guidance, especially because post-TACE symptoms may overlap with serious complications such as liver abscess, hemorrhage, sepsis, or liver failure.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill provides step-by-step instructions for TIPS, a high-risk invasive interventional radiology procedure, without an explicit warning that it is intended only for trained clinicians in an appropriately equipped setting and does not replace specialist judgment. Because the content is operational and actionable, an unqualified or insufficiently supervised user could treat it as a complete procedure guide, increasing risk of severe patient harm including hemorrhage, liver failure, or procedural complications.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill gives concrete WHO grading and molecular subtype outputs for diffuse gliomas based on imaging features, which can be interpreted as a clinical diagnosis rather than decision support. Because glioma classification depends on pathology and molecular testing, omission of an explicit warning and escalation requirement creates a real risk of overreliance, delayed biopsy/pathology confirmation, and unsafe treatment planning in a high-stakes oncology context.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill gives concrete diagnostic and management actions that could influence treatment, further testing, biopsy, or follow-up, but it does not clearly state that it is only an educational aid and cannot replace clinician judgment, institutional protocol, or specialist consultation. In a medical context, ambiguous automation or overreliance on such guidance can contribute to misdiagnosis, delayed diagnosis, unnecessary invasive procedures, or unsafe treatment decisions, making this materially safety-relevant.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill provides concrete invasive airway intervention decision logic and device parameters for stent placement and balloon dilation, but does not clearly state that it is only for trained clinicians in appropriate procedural settings. Because these are high-risk interventions involving airway injury, bleeding, and potentially fatal complications, omission of a strong professional-use warning increases the chance of unsafe reliance or unsupervised execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill provides step-by-step instructions for a high-risk invasive procedure without an explicit warning that it is restricted to trained, licensed clinicians in an appropriately equipped medical setting. Because balloon dilation can cause vessel dissection, rupture, thrombosis, bleeding, and organ injury, presenting the workflow without strong qualification and safety gating increases the risk of dangerous misuse by unqualified users or overreliance by automated agents.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill provides diagnostic guidance for spinal degenerative joint disease and explicitly states that plain X-ray can confirm the diagnosis, yet it does not include a user-facing warning that the output is not a substitute for clinician judgment. In a medical context, omission of such a warning can encourage overreliance on the skill for patient-care decisions, increasing the risk of misdiagnosis, missed alternative causes such as infection or trauma, and unsafe assessment of neurologic compression.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage instructions and all example prompts are presented solely in Chinese, and L308 explicitly tells users to invoke skills using the skill name as a prompt without indicating that other languages are supported. This can be read as forcing a specific language/locale for interaction, which is a natural-language policy concern when no user opt-in or alternative locale is offered.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 234)May include surrounding context.

md
<a href="https://www.star-history.com/">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=&type=date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=&type=date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=&type=date" />
 </picture>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 235)May include surrounding context.

md
<a href="https://www.star-history.com/">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=&type=date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=&type=date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=&type=date" />
 </picture>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 236)May include surrounding context.

md
<a href="https://www.star-history.com/">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=&type=date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=&type=date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=&type=date" />
 </picture>

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises clinical decision support and interventional radiology capabilities but does not clearly warn users that outputs are educational and cannot replace licensed physician judgment or supervised procedural training. In a medical context, omission of this boundary can encourage overreliance on the model for diagnosis or invasive care decisions, increasing patient-safety risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The interventional radiology section lists invasive procedures such as puncture, embolization, shunt creation, ablation, and stent placement without an accompanying safety warning that these are high-risk procedures requiring qualified operators, sterile technique, imaging guidance, and emergency backup. This increases the chance that an inexperienced user could treat the skill as operational guidance for real-world procedures, with potential for severe patient harm.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown skill forces a specific language for its name, description, triggers, and procedural instructions. The policy requires flagging language or locale constraints when the skill does not provide user opt-in or clearly document that the skill is intended for a justified region- or language-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill name, description, and body are entirely in Chinese, which imposes a specific language on users without any opt-in or stated locale constraint. Under the policy, language constraints should either offer user choice or be explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill gives a direct recommendation to urgently start anti-tuberculosis treatment and isolation based on an imaging pattern without an explicit limitation that this is decision support only and that treatment and infection-control actions require physician confirmation and adherence to local protocols. In a medical setting, users may over-trust the skill and act on incomplete information, creating risk of misdiagnosis, unnecessary treatment, inappropriate isolation, or failure to perform required confirmatory evaluation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill name, description, and all usage instructions are written entirely in Chinese, with no indication that users may choose another language or that the skill is intended only for a Chinese-speaking or region-specific context. Under the policy, a language or locale restriction without opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill name, description, triggers, and workflow are entirely in Chinese, and there is no indication that the user can choose another language. This can violate language/locale policy when a skill forces a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger conditions are broad enough to activate on general mentions of AI imaging systems or workflow optimization, which can cause the skill to engage outside clearly scoped clinical contexts. In a medical setting, over-broad activation increases the chance that the agent will provide workflow guidance for sensitive patient-data handling or clinical operations without appropriate safeguards, validation, or user-role checks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.