Back to skill

Security audit

biomarker-investigation-zhcn

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed PatSnap biomarker research helper that uses external life-science data sources and optional web search, with no evidence of hidden persistence, local data access, destructive actions, or exfiltration.

Install only if you are comfortable connecting PatSnap's external MCP service with your API key and allowing the agent to query life-science databases, with occasional web searches when MCP data is insufficient or freshness is needed. Treat medical, clinical, and patent-risk conclusions as research support that should be checked against authoritative sources and qualified experts.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill’s public description says it searches academic and patent literature about biomarkers, but the instructions authorize substantially broader collection and analysis across news, deals, companies, drugs, targets, and clinical trial data. This scope expansion can cause users or calling systems to grant the skill more trust and broader data access than they intended, undermining informed consent and least-privilege expectations.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill is presented as a biomarker literature/patent search tool, but internally it also directs the agent to assess potential patent infringement risk. Legal-risk assessment is a materially different function from document retrieval and can lead to higher-stakes analysis than users expect, especially in regulated R&D and IP contexts.

Context-Inappropriate Capability

Low
Confidence
88% confidence
Finding
The skill includes instructions for open-network searching after MCP retrieval, but this behavior is not declared in the skill’s stated purpose or setup expectations. Hidden use of external web sources can introduce privacy, provenance, and data-governance concerns because users may believe results come only from the disclosed PatSnap/MCP sources.

Static analysis

No suspicious patterns detected.