Back to skill

Security audit

医械供应商合规核查

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language medical-device supplier compliance checklist skill with no executable code, credential use, persistence, or hidden high-impact behavior.

Before installing, treat this as a document checklist aid rather than professional legal or regulatory advice. It appears safe from an agent-security perspective, but supplier names and commercial relationships should be anonymized as the skill recommends, and any compliance conclusions should be checked against current official regulations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The instruction requires all external releases to use a fixed Chinese branding string and forbids alternative naming forms. This is a natural-language policy constraint affecting language/locale presentation, but the document does not offer user opt-in or explain a region-specific compliance need.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The display name, category, and main body are written in Chinese, while the file provides no instruction that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
The manifest names the package entirely in Chinese ("医械供应商合规核查"), which indicates a fixed language presentation with no visible opt-in or alternative locale in this file. Under the policy rule, forcing a specific language without user choice can be a natural-language policy concern.

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
The score keys are entirely in Chinese (for example, "本地闭环" and "零凭据"), which can constitute a language/locale policy issue when the file provides no indication that Chinese was user-selected or that the skill is intentionally region-specific. Because this is natural-language content in a JSON file, it falls under the all-file-types policy check.

Static analysis

No suspicious patterns detected.