Back to skill

Security audit

MedXpert-REG-001 · 医械注册全球通关枢纽

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed medical-device regulatory reference skill with no execution code, credentials, persistence, or hidden data handling, though users should review its license wording and language/trigger behavior.

This skill is appropriate to install as a regulatory knowledge reference. Before redistributing it or using its content for training or commercial reuse, review the inconsistent license terms. For high-stakes registration decisions, verify cited official sources and use qualified RA/legal review.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The skill metadata declares an MIT license, but the copyright section adds extra restrictions such as prohibiting copying, resale, and model training. That makes downstream users and platforms rely on permissions they do not actually have, creating legal and supply-chain trust risk around reuse, redistribution, and integration.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger list includes broad terms like labels, software, validation, complaints, maintenance, and review that can appear in many unrelated conversations. In an agent ecosystem this can cause unintended activation, pulling the user into a specialized regulatory skill unexpectedly and potentially causing irrelevant guidance, context leakage across skills, or poor routing decisions.

Natural-Language Policy Violations

Medium
Confidence
75% confidence
Finding
The skill states that output defaults to Chinese without explicit user choice. This is mainly a usability and safety-routing issue: users may receive compliance guidance in a language they did not request, increasing the chance of misunderstanding in a high-stakes regulatory context.

Static analysis

No suspicious patterns detected.