Back to skill

Security audit

Surgery-PMPH-10edition

Security checks across malware telemetry and agentic risk

Overview

This skill is not malware, but it needs Review because it gives detailed medical treatment and procedure instructions without adequate safety boundaries.

Install only if you intend to use it as an educational or clinician-reviewed reference. Do not rely on it as standalone medical advice, prescribing authority, emergency guidance, or a substitute for licensed clinical judgment, current guidelines, institutional protocols, and specialist supervision.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (85)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The document explicitly forbids puncture as a diagnostic method, yet later recommends a surgical technique that begins with cyst puncture and aspiration. Even if the prohibition is aimed at diagnostic biopsy rather than controlled intraoperative decompression, the wording is inconsistent and can mislead an agent or clinician into performing a hazardous puncture outside the intended surgical context, risking cyst fluid spillage, anaphylaxis, and dissemination.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The README instructs users to consult the medical skill before every answer, but it does not place a clear point-of-use warning that the material is for education/reference only and not a substitute for licensed clinical judgment, local protocols, or urgent escalation. In a clinical context, omission of this warning increases the risk that users over-trust the skill and act on incomplete or generalized guidance during real patient care.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The example answers provide specific diagnostic and treatment recommendations, including drug choices, dosing, follow-up, and procedural guidance, without adjacent safety caveats or advice to seek specialist supervision. Because this is a medical skill, concrete treatment outputs can be copied directly into real-world care, creating a meaningful risk of patient harm if the information is outdated, incomplete, or applied without proper evaluation.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README instructs users to ask medical questions and rely on textbook-derived answers, but the point-of-use guidance shown to the agent lacks a clear safety disclaimer that outputs are educational only and not a substitute for clinician judgment. In a medical skill, this omission can increase the chance that users over-trust generated answers for diagnosis or treatment decisions, creating real-world patient safety risk.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The README encourages users to ask medical questions and obtain direct solutions from the manual without placing an immediate, prominent warning that outputs are educational only and not a substitute for clinical judgment. In a medical skill context, this can lead users to over-trust generated guidance for diagnosis or treatment decisions, increasing the risk of harmful real-world misuse.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This README presents detailed clinical guidance and example answers that could be used at the point of care, but the operative usage section does not clearly warn users that the material is educational only and not a substitute for licensed medical judgment. In a medical skill, omission of an explicit safety disclaimer increases the risk that users treat the output as authoritative treatment advice, potentially causing patient harm.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README gives operational usage instructions for a medical decision-support skill and even tells the agent to verify a medical skill before every answer, but it does not place a prominent warning near those instructions that the content is educational only and not a substitute for clinician judgment. In a medical context, this omission can cause users to over-trust model output for diagnosis or treatment, increasing the risk of harmful real-world decisions.

Vague Triggers

Low
Confidence
95% confidence
Finding
The SECURITY.md file leaves the vulnerability reporting section as generic placeholder text instead of providing an actual reporting channel or process. This can delay or prevent responsible disclosure, causing security issues to go unreported or be disclosed publicly without coordination.

Missing User Warnings

High
Confidence
96% confidence
Finding
This registry enumerates many emergency, invasive, and perioperative medical skills, including resuscitation, airway management, transfusion, anesthesia, and surgical procedures, yet it provides no visible safety boundary stating that the material is educational and not a substitute for licensed clinical judgment. In an agent setting, that omission can cause users or downstream systems to over-trust the skill as actionable bedside guidance, increasing risk of harmful medical decisions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger model is broad and underspecified, with descriptions like symptom clusters or clinical contexts but no invocation boundaries, exclusions, or negative examples. In an agentic system this can cause the wrong skill to activate during general discussion, preliminary triage, or incomplete-information scenarios, leading to inappropriate or overconfident clinical guidance.

Vague Triggers

Medium
Confidence
94% confidence
Finding
Some triggers are symptom-level phrases that are common in ordinary clinical conversation rather than explicit requests for a specific procedure or protocol. Because this registry covers high-risk emergency and invasive topics, such broad matching increases the chance of premature activation and unsafe recommendations before diagnosis or supervision is established.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill gives step-by-step invasive medical instructions, including Foley catheter placement, ventilator manipulation, percutaneous drainage, and decompressive laparotomy, without any explicit warning that this is high-risk guidance intended only for qualified clinicians under local protocols. In an agent setting, this omission increases the chance that unqualified users or over-trusting operators may act on dangerous recommendations without appropriate supervision, contraindication checks, sterility, dosing/procedural safeguards, or escalation pathways.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill gives concrete medical treatment instructions, including antibiotic selection, treatment duration, and estrogen therapy, without a visible safety disclaimer or requirement for clinician oversight. In a healthcare context, users may act on this guidance as personalized medical advice, creating risk of misdiagnosis, inappropriate antibiotic use, missed pyelonephritis or STI, and harm from contraindicated treatment.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill provides concrete diagnosis and rescue-treatment instructions for suspected acute transplant rejection, including biopsy, high-dose methylprednisolone, ATG/ALG escalation, plasmapheresis, and immunosuppression adjustment, but does not explicitly require immediate transplant-specialist supervision or emergency escalation. In this context, omission of a strong warning is dangerous because transplant rejection is a time-critical, high-acuity condition and these interventions carry substantial risk if applied without expert evaluation, monitoring, and differential diagnosis (for example infection vs rejection).

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill is entirely in Chinese without any language selection or confirmation, which can cause users or downstream agents to misunderstand emergency medical instructions. In a CPR skill, misinterpretation is especially risky because incorrect execution or failure to act quickly can directly affect patient safety.

Missing User Warnings

High
Confidence
98% confidence
Finding
This skill gives step-by-step instructions for a high-risk orthopedic reduction that can cause neurovascular injury, fracture, failed reduction, or anesthesia-related harm if attempted by an untrained person. Although the text mentions anesthesia and contraindications, it lacks a clear user-facing restriction that the procedure is only for qualified clinicians in an appropriate medical setting, which makes unsafe misuse more likely.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill provides step-by-step emergency airway and aspiration management instructions, including intubation, bronchoscopy, lavage, steroids, and prophylactic antibiotics, without any explicit boundary that it is informational support only for qualified anesthesiology clinicians. In a high-acuity setting, omission of this warning can encourage overreliance by unqualified users or unsafe execution without appropriate expertise, causing severe patient harm or death.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill provides clinical assessment and treatment-oriented guidance for traumatic urethral injury, including prognosis and use in later treatment decisions, without any disclaimer that it is only informational and not a substitute for licensed medical evaluation. In a medical context, omission of safety limitations can cause overreliance on the output, delayed specialist care, or inappropriate management of a potentially urgent injury.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger condition is extremely broad: it activates whenever a patient needs antibiotic treatment, which can cause the agent to apply this skill in routine or insufficiently contextualized clinical discussions. In a high-risk medical domain, over-triggering can lead to premature regimen recommendations without required patient-specific factors such as renal function, allergy history, pathogen data, pregnancy status, or infection source.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill provides step-by-step emergency clinical guidance for a life-threatening condition, including invasive biliary drainage options, resuscitation, vasopressors, steroids, blood products, and antibiotic use, but it does not clearly state that it is for licensed clinicians and not for laypersons. In this context, omission of qualification and safety boundaries is dangerous because misuse or over-trust could directly lead to patient harm, delayed definitive care, or unsafe performance of invasive procedures.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This skill provides a concrete decision procedure for preserving versus excising traumatically injured hand skin without any warning that it is only an aid and not a substitute for clinician judgment, specialist consultation, or formal protocols. Because debridement and tissue preservation decisions can materially affect perfusion, infection risk, functional outcome, and limb salvage, omission of that warning increases the chance that a user treats the checklist as authoritative in situations where bedside findings are equivocal or the injury is beyond the skill's safe scope.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill provides actionable guidance for selecting and carrying out invasive autologous transfusion procedures, including blood collection volumes, thresholds, and contraindications, but it does not state that this must only be performed by qualified clinicians under formal medical supervision. That omission is dangerous because a user could treat the skill as sufficient procedural authority for a high-risk medical intervention, leading to severe injury or death if applied incorrectly or outside appropriate perioperative settings.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This skill provides diagnostic criteria, recommends advanced and invasive tests such as ERCP and liver biopsy, and urges expedited Kasai surgery timing, but it does not explicitly warn that the content is only supportive and not a substitute for urgent specialist pediatric hepatology/surgical evaluation. In a high-stakes neonatal condition where delays or misclassification can cause irreversible harm, an agent could present this guidance too authoritatively and influence caregivers or non-specialists to make unsafe decisions.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill presents itself as something that should be used immediately after suspicion or diagnosis and directly links its output to prognosis and decisions about medication versus surgery, but it provides no warning that it is informational only and must not replace clinician judgment. In a medical context involving tuberculosis staging and invasive treatment decisions, this can lead users to over-trust the workflow and make unsafe or premature care decisions.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill gives concrete, high-risk treatment directives for hypotension, shock, fluid boluses, vasoactive therapy, and specific drugs without a prominent limitation that it is only decision support and must be used by qualified clinicians with full patient assessment. In this context, users could over-trust the algorithmic branching and apply unsafe interventions to the wrong patient, especially since CVP-guided resuscitation is oversimplified and the text includes imperative actions such as rapid fluid infusion and inotrope use.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.