Back to skill

Security audit

医疗器械出海经营

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only medical-device export business guide with no executable behavior, credential use, persistence, or hidden data handling.

Before installing, be aware this skill may activate for broad export or international-business wording; use it for medical-device international expansion decisions and verify legal, trade, and regulatory conclusions with current official sources or qualified professionals.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list contains very broad phrases such as “出口”, “国际业务”, “国际化”, and generic compliance/business terms that can appear in many unrelated conversations. This can cause unintended activation of the skill, pulling the agent into a specialized business/compliance workflow when the user did not request it, which increases the chance of irrelevant guidance, context hijacking, or accidental disclosure of business-oriented outputs in the wrong setting.

Static analysis

No suspicious patterns detected.