Insurance

Security checks across malware telemetry and agentic risk

Overview

This is a local insurance record organizer that stores user-entered policy and claim records in local JSON files, with no evidence of network access or hidden automation.

Install only if you are comfortable storing insurance policy numbers, insured names, premiums, renewal dates, and claim notes in local workspace files. Manage and delete memory/insurance data yourself when no longer needed, and do not treat the skill as insurance, legal, or purchasing advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill describes file read/write and likely script execution capabilities but does not declare permissions, creating a transparency and governance gap. Even though the stated behavior is local-only, this skill handles sensitive insurance and claims data, so undeclared capabilities can lead to unexpected access to local files or environment data and make review, sandboxing, and user consent weaker.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal