Back to skill

Security audit

医械标签与IFU专家

Security checks for vulnerabilities and agentic risk

Overview

The skill is a document-only medical-device labeling and IFU reference aid with no hidden execution, persistence, credential access, or data-changing behavior found.

Use this as a regulatory reference aid, not as a substitute for professional review or official agency decisions. Because some triggers are generic, invoke it in clear medical-device contexts and verify current regulatory and standards versions before relying on its output.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger list includes very broad terms such as '标签', '说明书', 'IFU', '符号', and references to common regulatory phrases. In an agent environment, such generic triggers can cause accidental invocation in unrelated conversations, leading the skill to activate unexpectedly and influence responses outside the user's intended context. While not directly enabling code execution, it can create context hijacking, unnecessary file loading, and misleading compliance guidance in the wrong workflow.

Static analysis

No suspicious patterns detected.