Back to skill

Security audit

医药企业综合情报(Pharma Company Intelligence)

Security checks for vulnerabilities and agentic risk

Overview

This is a purpose-aligned pharmaceutical intelligence report skill that reads optional user-provided documents and writes a session HTML report, with no evidence of hidden execution, credential use, or cross-session persistence.

Install only if you are comfortable with the agent using web, patent, paper, and PatSnap-style tools to research a named pharmaceutical company. Do not provide confidential PDFs, PPTs, or DOCX files unless you intend their contents to be read and used in the report. Expect a Chinese HTML report to be created in the session reports directory by default.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill accepts an optional 'reference_doc' and explicitly instructs the agent to read it and use it to shape downstream analysis, but the user-facing description does not clearly warn that uploaded files will be parsed and incorporated. This creates a consent and data-handling transparency issue, especially in a competitive-intelligence setting where uploaded PDFs or decks may contain confidential business information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Inputs table sets output_lang to default to “zh” while only optionally supporting English. This establishes a language preference without requiring the user to choose or opt in, which is a natural-language locale policy concern under the stated rules.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are broad natural-language requests like '帮我做一份 [公司名] 的调研报告' and '我想了解 [公司名] 的药物管线和专利情况', which are common user utterances and may cause the skill to activate in situations where the user did not intend this specific high-cost, document-reading, report-writing workflow. In this skill's context, unintended activation is more concerning because the workflow may ingest uploaded reference documents, perform extensive external lookups, and generate persistent session artifacts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a very broad pharmaceutical company intelligence capability but does not define clear activation boundaries, eligible inputs, or disallowed use cases. In an agent setting, this can cause overbroad triggering on loosely related prompts, increasing the chance of unnecessary external data access, unintended competitive-intelligence workflows, and user confusion about when the skill should run.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description mandates Chinese-oriented output and report structure without indicating user choice, locale negotiation, or a business justification for the restriction. This can lead to mismatched outputs, reduced transparency, and possible policy or usability issues when users expect language-neutral behavior or consent-based localization.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill states that it writes a complete HTML report to '@session/reports/<company_slug>_intelligence_report.html', but this persistence behavior is not clearly disclosed as a user warning. While session-local report generation is expected for reporting skills, undisclosed file creation can still surprise users and may leave sensitive competitive-intelligence outputs in the session workspace longer than expected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill metadata presents the display name primarily in Chinese with an English parenthetical, but the file does not state that language selection is optional or that the skill is intended for a Chinese-speaking context. This can violate language/locale policy expectations when users have not opted into that locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.