Back to skill

Security audit

Systematic Anatomy 10edition

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed anatomy education bundle, but it includes direct invasive medical and emergency-care guidance that needs careful review before use.

Install only if you want a medical anatomy reference for trained or supervised educational use. Do not rely on it for diagnosis, emergency triage, self-treatment, or performing procedures; users should add or require clinician-only and emergency-escalation guardrails before using the clinical subskills in a general agent environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (90)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill gives procedural instructions for a digital rectal exam and interpretive guidance without a clear user-facing warning that this is for qualified clinicians only. Because DRE is an invasive medical examination that carries privacy, consent, infection-control, and misdiagnosis risks, presenting it without strong safety boundaries could encourage untrained users to attempt it or overinterpret findings.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill provides step-by-step guidance for an invasive surgical drainage procedure, including incision selection and drain placement, but does not clearly restrict use to trained clinicians or warn lay users not to attempt it. In a general-purpose agent skill library, this omission is dangerous because non-professionals could interpret the content as actionable self-care or informal instruction, leading to serious injury, infection, bleeding, delayed definitive treatment, or damage to lactation structures.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill discusses infertility assessment, ectopic pregnancy, and tubal ligation planning but provides no user-facing warning that this is educational information rather than medical advice. Because ectopic pregnancy can be life-threatening and surgical decisions require licensed clinical judgment, omission of safety and escalation guidance creates a meaningful risk of delayed care or inappropriate self-management.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill gives actionable guidance for selecting a vas deferens ligation site in a sterilization procedure, including anatomical targeting and reasons for choosing the spermatic cord segment, but provides no safety boundary, clinician-only limitation, consent requirement, or warning against non-professional use. Because this is an invasive surgical procedure with risk of hemorrhage, nerve/vascular injury, infection, failed sterilization, and permanent reproductive harm, omission of safeguards materially increases misuse risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README includes concrete emergency stroke management guidance such as immediate CT, thrombolysis eligibility, and medication steps. Although the project has a general risk notice earlier, the example presents actionable real-world clinical instructions without a nearby, explicit warning that the content is educational only and must not be used for diagnosis, treatment, or emergency decision-making, which creates a foreseeable risk of unsafe reliance.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 199)May include surrounding context.

md
<a href="https://www.star-history.com/">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=&type=date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=&type=date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=&type=date" />
 </picture>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 200)May include surrounding context.

md
<a href="https://www.star-history.com/">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=&type=date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=&type=date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=&type=date" />
 </picture>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 201)May include surrounding context.

md
<a href="https://www.star-history.com/">
 <picture>
   <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=&type=date&theme=dark" />
   <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=&type=date" />
   <img alt="Star History Chart" src="https://api.star-history.com/svg?repos=&type=date" />
 </picture>

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The primary description is written as a Chinese-only skill description, and the usage examples are also only in Chinese. This creates a locale/language constraint without any explicit user choice, opt-in, or justification that the skill is intended only for Chinese-language users.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest frames this package as a set of anatomy skills based on a specific textbook, implying educational/anatomical analysis content. The listed subskill xin-xing-tai-jiao-cai-shu-zi-zi-yuan-huo-qu literally indicates digital resource acquisition, which goes beyond anatomy knowledge delivery and suggests resource retrieval behavior not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown skill forces a specific language for all user-facing description and instructions, which can violate language/locale policy when no opt-in or alternative is provided. The file does not indicate that the skill is region-specific or that Chinese is an explicit user-selected preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The entire skill is written only in Chinese and does not offer any language choice or indicate that the locale restriction is optional. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is written entirely in Chinese and does not indicate that language selection is optional or configurable. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger includes a broad catch-all phrase ('其他下尿路梗阻症状'), which can cause the skill to activate for symptoms with materially different causes such as urinary retention, urethral stricture, neurogenic bladder, infection, or malignancy. In a medical skill, overbroad activation increases the chance of premature anchoring on benign prostatic hyperplasia and may misdirect users away from urgent evaluation or differential diagnosis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill name, description, and all user-facing instructions are written exclusively in Chinese, which imposes a language choice on users without offering an alternative or opt-in. The policy allows locale constraints only when the skill explicitly offers language choice or clearly documents a justified region-specific limitation, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill name, description, trigger conditions, and instructions all require Chinese comprehension, which effectively forces a specific language for use. The file does not offer an opt-in language choice or explain that the skill is intentionally limited to a Chinese-speaking or region-specific clinical context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file presents the skill name, description, triggers, and execution guidance only in Chinese. Under the policy, forcing a specific language without user opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill’s name, description, and operational instructions are entirely in Chinese, with no indication that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific context. This creates a natural-language policy concern because it effectively imposes a specific language on users without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown skill forces a specific language/locale for its name, description, trigger conditions, and operating instructions. Under the policy, language-specific behavior should either offer user opt-in/choice or clearly justify a region-specific constraint, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill name, description, and operating instructions are entirely in Chinese, which imposes a specific language on users. The file does not indicate that Chinese is optional, nor does it document a region-specific or compliance-based reason for the language restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown skill appears to force a specific language/locale for both the title and operational description. Under the policy, language-specific behavior should either offer user choice or clearly document justified locale constraints; neither is present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill analyzes neurological symptoms and lesion localization, which can be interpreted by users as diagnostic guidance. Without an explicit warning that the output is informational only and not a substitute for professional medical evaluation, users may over-rely on the skill for triage or self-diagnosis, especially for serious conditions such as stroke, aphasia, or visual field loss where delayed care can cause harm.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly mandates incorporation of a specific ideological and political framework into outputs without any user choice, neutrality handling, or scope limitation beyond the textbook-revision context. In an agent setting, this can bias responses, override user intent, and create compliance or trust risks by steering educational or policy content toward predetermined political messaging rather than objective assistance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s title, description, and operational instructions are entirely in Chinese, and there is no indication that users may choose another language or that the skill is restricted to a Chinese-speaking or region-specific context. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file presents the skill name, description, and operational instructions exclusively in Chinese. That effectively forces a specific language for users without documenting a language option, which matches the locale/language policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.