Back to skill

Security audit

Medical Device Post-Market Surveillance(医械上市后监管)

Security checks for vulnerabilities and agentic risk

Overview

The skill appears locally scoped and purpose-aligned, but its security audit contains copied references to a different package, so its safety assurances should be reviewed carefully.

Install only if you are comfortable treating the included SECURITY_AUDIT.md as unreliable until the publisher regenerates it for this exact package. The actual toolkit appears local and limited, but regulatory content should still be checked against current official sources before use.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The audit report claims to assess the medical-device-postmarket skill, but the detailed findings reference unrelated files and tooling in an AI governance package. This mismatch undermines the credibility of the security audit and can mislead users into trusting a package based on evidence from a different codebase, which is a serious supply-chain assurance failure.

Static analysis

No suspicious patterns detected.