Back to skill

Security audit

Medical Device Cybersecurity(医疗器械网络安全)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local compliance helper with no network, credential, or privileged behavior; its bundled audit report has a package-name mismatch but that does not create runtime risk.

Before installing, treat the included regulatory material as a dated reference and verify current FDA, EU, and NMPA requirements for real submissions. The bundled SECURITY_AUDIT.md should not be relied on as a precise audit record until the mismatched file/tool names are corrected.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The report claims to audit a medical-device cybersecurity skill, but the detailed evidence references a different package and toolkit (`ai_governance_quality_test.py` and `ai_governance_toolkit.py`). This mismatch undermines the integrity of the security review and can mislead users into trusting a package that may not actually have been audited, creating a supply-chain trust gap.

Static analysis

No suspicious patterns detected.