Back to skill

Security audit

Medical Ip Director

Security checks for vulnerabilities and agentic risk

Overview

This medical marketing skill is disclosed as conversion-focused, but it encourages collection of facial photos and gives deletion assurances without a controlled privacy workflow.

Review carefully before installing. Use it only in a supervised medical-marketing workflow, avoid patient-identifiable data, remove casual photo-submission CTAs unless a compliant secure intake and consent process exists, and require human medical/legal review before publishing outputs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:42
Finding

Mandatory commercial lead-generation injection into generated content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:42-44, SKILL.md:78; corroborated by README.md:9 and README.md:34
Vulnerability Type: Mandatory output manipulation and commercial traffic diversion
Risk Level: High

Vulnerable Skill Instructions

The following is a faithful English translation of the relevant instructions in SKILL.md:42-44:

markdown
Every script must not be merely educational; it must have the purpose of
screening and conversion. A KOS action must be inserted at the end or in
the hook of the script:

- High-net-worth audience screening: Use high thresholds, high difficulty,
  and the need for exceptionally high-quality tissue to screen out users
  seeking cheap or free services and attract high-awareness,
  high-spending customers.

- Seamless CTA lead collection: Do not use overt sales language. Use reasons
  such as examining the patient's baseline condition, measuring tension,
  assessing anatomical structure, or reviewing images to direct users to
  send photographs or request a private consultation. The prompt must
  include a privacy statement.

The forced-output rule in SKILL.md:78 states:

markdown
- When the user enters `/script [duration/benchmark]`: execute Steps 2 and 6,
  and forcibly append a KOS lead-generation ending.

Technical Analysis

The Skill does not merely provide an optional medical-marketing capability. It establishes a persistent instruction that every generated script must serve a conversion purpose and that /script responses must contain a lead-capture ending.

This exceeds the minimum behavior needed to analyze source material or generate an educational medical script. It alters the Agent's output policy so that otherwise neutral requests are converted into commercial advertisements and private-consultation funnels. The behavior is mandatory rather than conditional on the user expressly requesting promotional conten ...[truncated 1453 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the requirement that every script contain screening or conversion content.
  2. Remove the instruction that forcibly appends a KOS lead-generation ending.
  3. Make promotional calls to action explicitly opt-in and generate them only when the user requests advertising or conversion copy.
  4. Separate educational and promotional modes, with educational mode as the default.
  5. Clearly label generated advertising content and require human legal and medical review before publication.
  6. Do not use medical assessment language as a pretext for collecting leads.
  7. Add a rule that the Agent must honor requests for neutral content without injecting contact, consultation, photograph-submission, or private-message prompts.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:34
Finding

Solicitation of sensitive facial and medical images using unenforceable deletion guarantees

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:34-35, SKILL.md:44; demonstrated by examples/short-video-example.md:16
Vulnerability Type: Unsafe collection of sensitive health and biometric information
Risk Level: High

Vulnerable Skill Instructions

The following is a faithful English translation of SKILL.md:34-35:

markdown
- All photographs, consultation information, and other private data provided
  by users are used only for temporary assessment and will not be stored,
  disclosed, or used for any other commercial purpose.

- When directing users to send photographs, it is mandatory to state:
  "The photographs are used only for professional assessment. They will be
  deleted immediately after the assessment and will not be retained."

The lead-generation example required by SKILL.md:44 states:

markdown
Celebrity photographs are useless. Send your original, unedited front and
side photographs, and I will assess your skin-tension baseline. The
photographs are used only for assessment, will be deleted immediately after
review, and will never be retained.

The implemented example in examples/short-video-example.md:16 states:

markdown
Want to know whether your condition can be repaired? Send original,
unedited front and side photographs, and I will assess your tissue baseline.

Technical Analysis

The Skill actively encourages users to submit unedited front and side facial photographs for medical assessment. Such images may constitute identifiable health information and biometric data, particularly when combined with treatment concerns or consultation records.

The package contains only Markdown instructions and examples. It provides no implementation for secure transmission, consent recording, access control, encryption, retention enforcement, deletion verification, incident response, or data-subject requests. Consequently, the assertions that photo ...[truncated 1985 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove photograph solicitation from default generated content.
  2. Do not claim that data will be deleted immediately or never retained unless the complete downstream system technically enforces and independently verifies that policy.
  3. If photographs are essential, require an approved secure clinical channel rather than private messages or unspecified communication services.
  4. Present a reviewed privacy notice before collection, identifying the controller, processing purpose, legal basis, recipients, retention period, deletion process, and user rights.
  5. Obtain explicit and informed consent before receiving facial or medical images.
  6. Implement encryption in transit and at rest, role-based access control, audit logging, retention limits, verified deletion, backup handling, and incident-response procedures.
  7. Minimize collected data and offer non-image alternatives whenever possible.
  8. Prohibit medical assessment from casual social-media images unless an authorized medical professional and compliant clinical workflow are involved.
  9. Add automated checks ensuring that no generated CTA solicits sensitive data outside the approved workflow.
  10. Subject all medical and privacy language to qualified human review before publication.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented trigger commands accept broad free-form inputs such as doctor interview text, benchmark links, and hot-topic prompts without defining scope limits, allowed content types, or exclusion conditions. In a medical marketing context, this can cause the skill to generate non-compliant promotional claims, process sensitive personal or health-related data, or follow unsafe user-supplied references in ways that increase regulatory, privacy, and misuse risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README advertises exporting and maintaining a doctor content matrix but does not explain what information may be stored, how long it persists, who can access it, or whether sensitive source material is included. Because the skill is designed for medical and cosmetic practices, retained content may contain proprietary business strategy, clinician statements, or personal/health-adjacent information, creating confidentiality and privacy exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description and memory rules indicate ongoing maintenance of a 'super content matrix,' which implies persistence across turns, but there is no clear user-facing warning that information may be retained or written into a knowledge base. In a medical context, users may share sensitive health-related details, so silent persistence materially raises privacy and compliance risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction to maintain and update a persistent content matrix across multi-turn interactions creates a natural-language data retention pathway. In this skill's medical marketing context, accumulated user inputs could include sensitive health, image, or consultation information, making persistence more dangerous than in a generic content-generation skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill promises that user photos and consultation data will not be stored, but other sections instruct the agent to maintain and update a persistent matrix and perform forced archiving. Even if the author intended to archive only public medical knowledge, the instructions create a contradictory retention model that could cause conversation-derived personal or health information to be preserved unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow mandates a forced archive-generation step without an explicit warning that a file or persistent record will be created or updated. Because the skill solicits conversational and potentially health-adjacent input, automatic persistence can surprise users and lead to unauthorized retention of sensitive material.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

A workflow step that forces archiving semantically instructs preservation of conversation-derived information. Given the skill also encourages users to send photos for evaluation, the combination increases the risk that sensitive personal or health-related material could be retained beyond the immediate session.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The '/save_matrix' trigger explicitly instructs the model to persist accumulated material on demand, but the skill does not adequately constrain what may have been accumulated beforehand. In a medical-adjacent workflow that invites private images and assessment details, this can turn transient sensitive input into a persistent record.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script explicitly asks users to send front and side facial photos for medical-style evaluation, which involves highly sensitive biometric and health-adjacent personal data. There is no privacy notice, consent language, retention policy, or secure submission guidance, creating risk of oversharing, improper collection, and mishandling of sensitive user information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill content is written in Chinese and presents fixed Chinese-language headings and messaging, with no indication that another language can be used or that the locale is intentionally limited. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script explicitly asks users to send front and side facial photos for a medical-style assessment, which involves sensitive biometric and health-related personal data. There is no accompanying privacy notice, consent language, retention policy, or secure submission guidance, increasing the risk of inappropriate collection, misuse, or exposure of highly sensitive data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The README presents the skill entirely in Chinese without offering an alternative language or stating that the skill is intended only for Chinese-speaking users. This can constitute a language/locale policy issue when no user choice or explicit justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language instructions, triggers, and output rules are all presented in Chinese, and there is no indication that users may choose another language. Under the policy, forcing a specific language without opt-in can be a locale-policy issue unless the restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. The entire skill content is written only in Chinese and does not indicate that language selection is optional or that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

All user-facing content in the file is presented only in Chinese, with no indication that users can choose another language or that the skill is explicitly limited to a Chinese-speaking audience. This can constitute a language/locale policy issue when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.