Back to skill

Security audit

靶点药物BD综合评估(Target-Drug BD Assessment)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language workflow for producing oncology target and drug BD assessment reports, with no executable code, credentials, or hidden persistence.

Installers should understand that this skill is intended for Chinese-language oncology R&D and BD report generation. It may use external domain tools and web search to gather business, clinical, patent, and literature evidence, and deep-report mode may create an HTML file in session outputs. Users should treat its outputs as decision-support material, not medical, legal, valuation, or formal FTO advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and the entire skill content are written exclusively in Chinese, and the skill specifies required outputs and workflow in that language without offering the user a language choice. This creates a natural-language locale policy issue because the skill appears to enforce a specific language by default rather than allowing opt-in or documenting a region-specific constraint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest context says the skill is for integrating target evidence, pipeline, patents, and deals for BD evaluation, collaboration screening, and diligence. This file instead defines a much larger '研发立项报告生成器' workflow with 21 sections covering topics like epidemiology, regulation, health economics, ROI/NPV, CMC manufacturability, and HTML presentation generation, which goes beyond a BD assessment-focused scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

Sections on regulatory path, drug economics, development cost and ROI, and CMC manufacturability introduce specialized assessment domains beyond the manifest's stated scope of integrating biological evidence, pipeline, patent, and deal information for BD evaluation. These analyses may be useful in some contexts, but they are not explicitly declared and materially broaden the capability surface of the skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description focuses on integrating evidence for assessment and diligence use cases, but does not mention file generation or producing browser-openable HTML artifacts. Persisting a versioned HTML report is a user-visible behavior expansion beyond a pure assessment/synthesis description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The instruction to save generated HTML to session storage introduces a write-side effect without clearly requiring user awareness or consent. While the storage target is limited and not obviously sensitive, undisclosed file creation can surprise users, create unwanted persistence, and normalize silent writes by agent skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description is written only in Chinese, which can impose a language preference without any indication of user opt-in or a documented locale-specific purpose. The policy requires either offering language choice or clearly justifying the locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.