Back to skill

Security audit

生物医药FTO分析(Biopharma FTO Analysis)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese-language workflow for preliminary biopharma FTO patent analysis, with no executable code, credentials, persistence, or hidden data access in the inspected artifacts.

Install this only if you are comfortable using a Chinese-language preliminary FTO workflow. Treat outputs as research support, not legal advice, and have qualified patent counsel review any high- or medium-risk conclusions before business decisions.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill is written entirely in Chinese without offering a language choice, which can prevent users or supervising systems from accurately understanding scope, limitations, and required inputs. In a legal-risk workflow like FTO screening, language mismatch can cause users to miss critical disclaimers, misuse the skill, or provide incomplete inputs, leading to incorrect risk assessments and unsafe downstream decisions.

Static analysis

No suspicious patterns detected.