Back to skill

Security audit

微生物组疾病机制研究(Microbiome Disease Research)

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed research-and-reporting helper for gut microbiome literature and patent searches, with no evidence of hidden execution, credential use, persistence, or destructive behavior.

Install this if you want an agent to search PatSnap for gut microbiome patent and paper sources and generate local HTML/Markdown research reports. Do not treat the output as medical advice, and be aware the skill covers food/nutrition, patent analysis, and AI training-data collection topics in addition to microbiome-disease research.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The skill metadata says it is for microbiome–disease evidence chains and hypothesis generation, but the body expands into food-domain fine-tuning data collection, patent retrieval, and large-scale HTML report generation. This scope drift can cause the agent to activate in contexts the user did not intend, increasing the chance of inappropriate tool use, over-collection of data, or actions outside the reviewed trust boundary.

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
The trigger conditions materially broaden activation to probiotics, prebiotics, fermented foods, patents, and food-AI training tasks that exceed the stated disease-mechanism research purpose. Overbroad triggers create an invocation-scope vulnerability: the system may load this skill for unrelated requests and then perform searches or generate outputs the user did not specifically authorize.

Intent-Code Divergence

Medium
Confidence
80% confidence
Finding
The Guardrails present the skill as only doing literature research and report generation, while the workflow and dependencies explicitly include patent retrieval and patent-oriented analysis. This inconsistency is dangerous because downstream reviewers or orchestration systems may rely on the guardrails text and underestimate what the skill actually does, weakening policy enforcement and user transparency.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.