Back to skill

Security audit

precision-oncology-zhcn

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese-language precision-oncology research skill that uses a PatSnap MCP service for relevant life-science data retrieval.

Install this only if you intend to use PatSnap's life-science MCP service for oncology research and are comfortable storing/using a PatSnap API key in your agent's MCP configuration. For patient-specific medical decisions, verify outputs with qualified clinical sources because this skill is structured for research and business-development reporting, not direct medical care.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill is configured to auto-load for broad topics like cancer, tumor, carcinogenesis, and treatment, which are common in general medical discussions. Overbroad activation can cause the skill to engage unintentionally, steering users into a vendor-specific workflow and forcing pre-query MCP connectivity checks even when the user did not request this specialized behavior.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill description is fixed in Simplified Chinese and targets a China-language context without an explicit user language selection mechanism. In practice, this can cause responses to be delivered in an unexpected language or regional framing, increasing the risk of user misunderstanding in a medical domain where terminology precision matters.

Static analysis

No suspicious patterns detected.