Back to skill

Security audit

微生物组疾病机制研究(Microbiome Disease Research)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed microbiome literature and patent research report generator, with some scope-label inconsistency but no hidden or malicious behavior found.

Before installing, verify that you want a Chinese-first gut-microbiome landscape skill that uses PatSnap patent/paper search and writes HTML reports. Ask for English or bilingual output when needed, and treat outputs as research summaries rather than medical advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description materially misrepresents the skill’s purpose: it advertises a food/nutrition gut-microbiome literature panorama workflow, while the stated skill purpose is microbiome–disease mechanism evidence-chain analysis and hypothesis generation. This can cause users, reviewers, or orchestration systems to invoke the skill under false assumptions, leading to inappropriate use, misleading outputs, and weakened trust or governance over high-impact research tasks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill metadata promises microbiome–disease evidence-chain analysis and hypothesis generation, but the body broadens the scope to food-domain landscape reporting and AI fine-tuning data collection. This kind of scope drift can cause the agent to activate in contexts the user did not intend, leading to over-collection, incorrect tool usage, and outputs that do not match the declared safety and purpose boundaries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented triggers and workflow include patent searches, applicant analysis, IPC classification, TRL assessment, and model fine-tuning guidance, which materially exceed the stated disease-mechanism research purpose. In an agent setting, this mismatch is dangerous because routing and user trust often depend on the manifest; a broader hidden behavior can trigger unrelated data-gathering and produce outputs outside the expected domain controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest hardcodes Chinese-language output in the description without user opt-in or justification, which can create silent mismatches with user expectations, downstream parsers, or review workflows that assume another language. In a research skill, this increases the risk of misunderstanding evidence, missing nuance in safety review, or producing unusable outputs for the requesting environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language instruction in the default prompt is explicitly written in English and directs use of the skill in that language, while the file does not offer any user choice of language or locale. This can violate language/locale policy expectations when a skill should not force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The title and the entire template are written as a Chinese-only reporting specification, which indicates a fixed language/locale expectation. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file presents all instructions, labels, and query template context only in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative language option or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file presents its primary instructions and taxonomy in Chinese, which can impose a language preference on users without explicit opt-in. The policy for this category flags language or locale constraints when the file does not offer a user choice or justify the restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.