Back to skill

Security audit

药物研发潜力评估(Drug Potential Assessment)

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed drug-assessment workflow that calls specialized research tools, with packaging gaps but no evidence of hidden, destructive, or data-stealing behavior.

Before installing, confirm you have access to the listed MCP data services and are comfortable with broad external research queries for pharma, patent, company, clinical, sequence, and chemistry data. The skill may be expensive or slow because it asks the agent to run many mandatory searches, and the package metadata should be tightened to declare those dependencies clearly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
这是明显不匹配。描述宣称该技能具备药物成药性、差异化和商业潜力评估能力,但实际代码没有实现任何相关逻辑、数据处理、模型分析或外部资源访问;它只是输出一条准备就绪的消息。虽然代码没有隐藏额外能力,但其主要用途与声明的核心功能严重不符,因此应判定为 mismatch。

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
Line L295 states '报告语言:中文为主,药物名称/靶点名称保留英文', which imposes a language preference in the skill instructions. The file does not offer the user a language choice or explain a justified region-specific requirement, so this is a natural-language locale policy violation.

Natural-Language Policy Violations

Low
Confidence
96% confidence
Finding
The default prompt is hardcoded in English ('Use $drug-potential-assessment...') while the rest of the interface contains Chinese text, and there is no indication that users can choose their preferred language. This creates a natural-language policy concern because it imposes a specific language without explicit opt-in or justification.

Vague Triggers

Medium
Confidence
88% confidence
Finding
This manifest identifies the skill by name but provides no description or trigger guidance, leaving activation scope unspecified. For manifest files, missing specificity on trigger scope or constraints can make invocation behavior ambiguous and increase the risk of unintended use.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.