Back to skill

Security audit

Evidence-Based Technical Labeling

Security checks for vulnerabilities and agentic risk

Overview

This skill is a governed technical-labeling workflow with optional PatSnap enrichment, and its sensitive behaviors are disclosed, gated, and purpose-aligned.

Before installing, decide whether your records may be sent to PatSnap or any external MCP service, and keep that authorization narrow. Treat disease-treatment labels as taxonomy outputs for technical evidence review only; have qualified subject-matter, legal, or regulatory reviewers approve any downstream medical, marketing, or compliance use.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The taxonomy contains explicit disease-treatment and medical-effect labels such as treatment of respiratory, urinary-system, skin, and sensory disorders without any caution that these are classification labels rather than validated medical claims or jurisdiction-specific regulatory categories. In a skill that operationalizes taxonomy-driven labeling and evidence enrichment, this can cause downstream systems or users to normalize, surface, or reuse regulated treatment claims without safeguards.

Static analysis

No suspicious patterns detected.