Back to skill

Security audit

单药全生命周期评估(Single-Drug Lifecycle Evaluation)

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for drug due-diligence reporting, but deep HTML reports are instructed to load mutable third-party JavaScript that could see sensitive report content when opened.

Review this skill before installing if reports may contain confidential pipeline, BD, investment, or patent information. Prefer a version that vendors ECharts locally or pins an exact CDN version with SRI, and confirm the report language and formatting match your users' needs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/legacy-report-spec.md:352
Finding

Unpinned Remote JavaScript Dependency in Generated HTML Reports

Content
View full analysis

Vulnerability Details

File Location: references/legacy-report-spec.md, line 352
Vulnerability Type: Mutable third-party JavaScript loaded from a remote CDN
Risk Level: Medium

Complete Code Snippet:

markdown
**ECharts CDN引用:`https://cdn.jsdelivr.net/npm/echarts@5/dist/echarts.min.js`**

Technical Analysis

The deep-report specification requires generated HTML reports to load ECharts as executable JavaScript from jsDelivr. The dependency uses the mutable major-version selector @5 instead of an exact, reviewed version. It also does not require Subresource Integrity verification.

Consequently, the JavaScript executed by a report viewer may differ from the content available when the Skill was audited. A compromise of the package release process, npm distribution path, CDN infrastructure, or dependency resolution process could cause generated reports to execute substituted JavaScript.

This is classified as an insecure dependency rather than confirmed malicious remote payload behavior: the repository contains no evidence that the specified CDN currently serves malicious content. The risk arises from mutable external executable content and the absence of integrity controls.

Attack Path

  1. A user requests a report using the deep format.
  2. The Agent follows the specification and generates HTML referencing https://cdn.jsdelivr.net/npm/echarts@5/dist/echarts.min.js.
  3. The user opens the generated report in a browser while network access is available.
  4. The browser resolves the mutable @5 selector and downloads JavaScript from the external CDN.
  5. If the upstream package or CDN delivery path has been compromised, attacker-controlled JavaScript executes in the report's browser context.

Impact Assessment

Exploitation would grant the substituted script the privileges available to JavaScript in the generated report's browser context. It could:

  • Read drug, clinical, transaction, and preliminary patent information rende ...[truncated 606 chars]
Remediation
View remediation

Remediation Suggestions

  1. Prefer a locally vendored, reviewed ECharts build so generated reports do not depend on remote executable content.
  2. If CDN delivery is unavoidable, pin an exact immutable version rather than the mutable @5 selector.
  3. Require a verified Subresource Integrity hash and crossorigin="anonymous" on the script element.
  4. Add a restrictive Content Security Policy that permits scripts only from explicitly approved sources and blocks unnecessary outbound connections.
  5. Record the exact dependency version, integrity hash, review date, and source in the report-generation specification.
  6. Consider generating static charts or sandboxing reports where confidentiality or offline review is required.

A hardened reference should follow this pattern, using an exact version and the verified hash for that exact artifact:

html
<script
  src="https://cdn.jsdelivr.net/npm/echarts@EXACT_VERSION/dist/echarts.min.js"
  integrity="sha384-VERIFIED_HASH"
  crossorigin="anonymous"></script>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill’s natural-language description and all operating instructions are written exclusively in Chinese, with no indication that users may choose another language or that the skill is limited to a Chinese-language/regional context. Under the policy, forcing a specific language without user opt-in is a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-codes Chinese-language output and presentation conventions in the core description, which can override a user's preferred language and create misleading or inaccessible outputs for users who expect another language. While this is not a classic memory-safety flaw, it is a real safety/quality vulnerability because it reduces user control, can impair review of regulated content, and may cause downstream misunderstanding in due-diligence or compliance contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The HTML specification mandates Chinese font and style rules without opt-in, forcing a presentation layer that may conflict with accessibility needs, enterprise standards, or the user's requested language. In this skill's context—producing investment, regulatory, and patent-related reports—forced formatting increases the risk of miscommunication, failed rendering, and reduced auditability across international stakeholders.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description is written entirely in Chinese and the stated output at L29 is also a Chinese-language report, suggesting the skill is intended to operate in a fixed language. Under the policy, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill metadata presents the primary display name in Chinese with an English translation in parentheses, but there is no indication that the user can choose their preferred language or locale. This may violate language/locale policy expectations when a specific language presentation is imposed by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.