Back to skill

Security audit

药物组合协同分析(Drug Combination Synergy Analysis)

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed drug-combination research workflow with no evidence of hidden code execution, credential use, persistence, or data exfiltration.

Install only if you are comfortable with the agent querying external pharma, literature, patent, and chemical-analysis tools and creating a Word report. Treat the generated ADMET and synergy conclusions as research hypotheses requiring expert review and experimental validation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向药物联合研究的分析型技能,但实际代码只是一个最小占位脚本,没有读取输入、执行分析、调用模型、访问数据源或输出任何与药物组合相关的结果。其实际主要行为与声明用途存在实质性不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest specifies a Word report output as "中文楷体+英文Times New Roman," which imposes a specific language/locale formatting requirement in the skill definition. Under the policy, forcing a specific language or locale without offering user choice or documenting justified regional scope is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The input parameter documentation sets output_lang to cn by default, which imposes a specific language choice unless the user explicitly overrides it. This is a natural-language locale policy concern because the skill defaults to one language rather than presenting a neutral choice or requiring explicit user preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.