Back to skill

Security audit

Pathophysiology-PMPH-10edition

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only medical education skill pack, but several included skills give high-stakes clinical treatment or end-of-life decision instructions without enough per-skill safeguards.

Install only if you want a medical education/reference pack and will treat it as study material or clinician-reviewed decision support. Do not rely on it alone for diagnosis, treatment, medication selection, invasive procedures, ICU decisions, brain-death determination, withdrawal of life support, or emergency care; use current official guidelines, local protocols, and qualified medical professionals.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (152)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill gives direct, actionable medical intervention guidance for manipulating apoptosis in serious diseases, including named drugs, radiation, gene transfer, and pathway-specific suppression, without any warning that this is educational content only or that it requires clinician oversight. In an agent setting, such content could be surfaced as treatment advice and lead to unsafe self-medication, off-label use, or harmful clinical decisions, especially because recommendations are simplified and omit contraindications, dosing, patient selection, and evidence limits.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill asserts alignment with the 2021 Chinese brain-death standard while presenting an internally inconsistent five-criteria rule, which can mislead users into believing the process is standardized and authoritative when it may not be. In high-stakes end-of-life determination, such misstatement can contribute to false brain-death determinations, inappropriate organ-donation workflows, and wrongful cessation of treatment.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The apnea assessment is described as '拔管后观察10分钟' (observe after extubation), which is inconsistent with standard controlled apnea testing and can be interpreted as removing ventilatory support in an unsafe manner. In a brain-death determination skill, procedural ambiguity can directly cause patient harm, invalid diagnosis, or premature withdrawal of life support.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs obtaining cerebrospinal fluid and references lumbar puncture as a way to get the sample, but it does not provide a clear procedural-risk warning, contraindications, or a requirement that the procedure be performed only by qualified clinicians in an appropriate setting. In a medical skill that could influence care decisions, omission of invasive-procedure safety context can lead to unsafe use, delayed recognition of complications, or inappropriate self/low-supervision attempts.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill gives concrete instructions for altering reperfusion pressure, temperature, and electrolyte composition in organs such as the heart, brain, liver, and kidney without requiring specialist supervision, patient-specific constraints, or escalation to formal clinical protocols. These are safety-critical medical parameters; if followed by an unqualified user or applied outside tightly controlled settings, they could cause severe tissue injury, arrhythmia, osmotic disturbances, graft damage, or death.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill provides concrete medical decision-making guidance for identifying a dominant pathological process and prioritizing treatment, but it contains no warning that this is educational content and not a substitute for licensed clinical judgment. In a medical context, omission of a professional-care disclaimer can encourage overreliance by non-clinicians or unsupported autonomous use, creating risk of harmful or delayed treatment.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This skill provides actionable medical triage-style guidance such as when to allow fever to continue versus when to actively reduce it, but it does not warn that the content is not a substitute for clinician judgment. Because the topic involves temperature thresholds up to 43℃, infection, immune status, and cancer care, users could rely on the output for real health decisions and delay appropriate treatment or undertake unsafe self-management.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill provides concrete oxygen-therapy instructions for a life-threatening condition without an explicit warning that it is intended only for qualified clinicians under medical supervision. Because the content includes target blood-gas values and dosing-style limits, an unqualified user could treat it as actionable bedside guidance, creating a substantial risk of hypoxemia, worsening hypercapnia, respiratory acidosis, or delayed escalation of care.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill gives concrete pharmacologic and biologic intervention guidance for ischemia-reperfusion injury, including NSAIDs, prostacyclin, monoclonal antibodies, antioxidants, and metal-binding agents, without any explicit warning that these measures require clinician oversight, indication-specific judgment, dosing validation, and contraindication screening. In a medical context, this omission can cause unsafe autonomous use, inappropriate treatment selection, delayed escalation, or medication-related harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill gives concrete first-line medication recommendations for hyperglycemia, dyslipidemia, hypertension, and hyperuricemia without a clear, prominent warning that treatment must be individualized and confirmed by a licensed clinician. In a medical skill aimed at prevention/management, users may overgeneralize these drug suggestions despite important contraindications, comorbidities, renal status, pregnancy status, dosing needs, and monitoring requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill gives procedural guidance for deliberately inducing ischemia/reperfusion, including cuff inflation on limbs and repeated occlusion cycles, without requiring clinician oversight, patient selection criteria, contraindications, monitoring, or emergency response guidance. Even though it limits use to planned ischemic settings and excludes acute MI/stroke, the content could still be misapplied by non-professionals or used in inappropriate patients, risking tissue injury, thrombotic/vascular complications, nerve damage, or delayed urgent care.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill gives specific vasoactive treatment guidance for septic shock, including when to consider dobutamine or norepinephrine, but does not clearly state that this is decision support only and must not replace clinician judgment, bedside hemodynamic assessment, or local sepsis protocols. In a high-acuity condition where misclassification can rapidly cause harm, omission of that warning increases the risk of unsafe autonomous or overconfident use.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This skill provides mental-health classification guidance for ASD, PTSD, and adjustment disorder without any explicit warning that it is not a substitute for professional diagnosis, and without crisis-oriented safety guidance. In a mental-health context, users may rely on the output to self-diagnose or delay urgent care, which is especially dangerous when symptoms could involve suicidality, psychosis, catatonia, severe agitation, or underlying medical causes.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill provides concrete treatment-oriented recommendations such as lactulose, rifaximin, protein restriction, and liver-support strategies without an explicit warning that this is clinician-facing medical guidance requiring qualified professional judgment. In a high-risk context like hepatic encephalopathy, omission of such safeguards can encourage overreliance by unqualified users or inappropriate application without confirmation of diagnosis, contraindications, or urgency of escalation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill name, description, headings, and instructions are entirely written in Chinese, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-language or region-specific context. This creates a natural-language policy concern because it implicitly enforces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill’s name, description, and operating instructions are entirely in Chinese, with no indication that users may choose another language or that the skill is intended only for a Chinese-language or region-specific environment. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language content of the skill is entirely in Chinese, and there is no indication that the skill is intended only for a Chinese-language audience or that users may request another language. This creates a language-policy concern because it imposes a locale/language choice without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing name, description, and operating instructions entirely in Chinese. Under the policy rules, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill name and all instructional content are written exclusively in Chinese, with no indication that users can choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. This is a natural-language policy concern because it imposes a specific language by default rather than offering opt-in or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file’s name, description, and all operational guidance are written exclusively in Chinese, which indicates a fixed language/locale expectation. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.