Back to skill

Security audit

MedXpert-CONT-001 · 官网与内容运营规范

Security checks for vulnerabilities and agentic risk

Overview

This is a MedXpert brand/content operations guide with no executable code, background behavior, credential handling, or undisclosed system access.

Install this only if you work on MedXpert-owned content or website operations. Users should still review outputs for brand, regulatory, copyright, and citation requirements, especially where the guide discusses rewriting third-party materials or keeping public wording free of technical AI terms.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill contains contradictory governance: one section requires prominent human-facing prompts to install the MedXpert AI skill, while another bans human-visible references to AI capability. This inconsistency can cause operators or downstream agents to produce policy-violating content, evade review expectations, or present misleading disclosures about how the service works.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are overly broad and include generic topics such as website operations, copywriting, SEO, and sync workflows, which can cause the skill to activate in unrelated conversations. Overbroad activation increases the chance of unintended instruction injection into tasks outside MedXpert's scope and may bias outputs toward this brand-specific playbook when it is not appropriate.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The manifest description advertises very broad applicability across website visuals, public copy, synchronization, SEO, AI indexing, and external materials, without stating when the skill should not be used. This makes accidental invocation more likely and can cause an agent to apply proprietary or organization-specific rules to unrelated domains or users.

Static analysis

No suspicious patterns detected.