Back to skill

Security audit

药物研发潜力评估(Drug Potential Assessment)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed drug-development research workflow that calls specialized pharma, patent, company, sequence, and chemistry tools, with no evidence of hidden execution, persistence, exfiltration, or destructive behavior.

Install only if you expect this skill to run broad pharma and patent intelligence searches. Be aware that its trigger language is broad and its manifest does not list the required MCP dependencies, so users should confirm available tools and costs/quotas before relying on it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向药物研发决策的分析技能,但提供的代码块仅包含一个最小化入口脚本,作用是输出一条就绪消息。代码没有任何数据处理、模型调用、药物属性分析、比较逻辑、外部资源访问或触发实现,因此其实际行为与声明的核心目的存在明显且实质性的不一致。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

L011 规定“当用户输入适应症、研究领域或靶点(可三者组合),本 Skill 自动触发”,触发条件几乎覆盖大量常见生物医药咨询表达,但未限定触发渠道、触发词或排除场景。虽然文档给出了示例,但没有提供负例或更明确的边界,容易导致用户只是在一般讨论相关主题时也被调用该技能。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.