Back to skill

Security audit

医械风险管理专家

Security checks for vulnerabilities and agentic risk

Overview

This is a document-only medical device risk-management reference skill with no hidden execution, credential access, or persistence found.

Use this as a Chinese-language drafting and checklist aid for medical device risk-management files. Before relying on outputs, verify current ISO, NMPA, FDA, EU, and PMDA requirements, and review the package's attribution and restrictive knowledge-content terms if you plan to redistribute or reuse the material.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file explicitly mandates a specific branding form ("品牌署名统一用『注册老炮 (Regulatory Veteran)』") for every external release without any user opt-in, configurability, or justification. In an agent skill, hard-coded authorship/branding requirements can pressure downstream outputs to include undisclosed attribution or endorsement language, which is a policy and provenance risk rather than a memory-safety issue.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger phrases are very broad and cover common regulatory and risk-management terms, which can cause the skill to activate in conversations where the user did not intend to invoke this specialized workflow. Overbroad activation can misroute user inputs, expose unrelated content from bundled references, or override more appropriate agent behavior in sensitive compliance contexts.

Static analysis

No suspicious patterns detected.