Back to skill

Security audit

保险理赔维权辅助分析

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent insurance-claim appeal assistant, but users should redact sensitive identity and medical details where possible.

Install only if you intend to use it for insurance claim-denial analysis. Before pasting case materials, redact nonessential ID numbers, phone numbers, addresses, policy numbers, and unrelated medical records, and review any generated appeal or complaint with a qualified professional when legal or medical judgment is needed.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list is broad and includes generic phrases like '拒赔' and '理赔纠纷', which can activate the skill during ordinary insurance conversations that are not intended to invoke a structured legal-financial workflow. In this skill's context, unintended activation is more concerning because the workflow solicits sensitive claims, medical, and policy data and provides quasi-legal dispute guidance, increasing privacy and misrouting risks.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly asks for highly sensitive data including policy numbers, medical records, diagnosis details, claim amounts, and rejection notices, but provides no explicit privacy warning, minimization guidance, or handling precautions before collection. In a legal-financial and health-related dispute context, this creates elevated risk of unnecessary exposure of personal, medical, and insurance identifiers if the skill is triggered accidentally or users overshare raw documents.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The template explicitly solicits highly sensitive personal data, including identity number, phone number, policy details, and medical claim materials, but provides no privacy notice, minimization guidance, redaction advice, or retention/secure transmission instructions. In the context of insurance claim disputes, these fields are especially sensitive and could expose users to privacy breaches, identity theft, or unnecessary over-disclosure if the template is copied, shared, or transmitted insecurely.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The template explicitly asks for highly sensitive personal data such as a full name, national ID number, phone number, and address, but provides no privacy warning, minimization guidance, or handling instructions. In the context of an insurance-claim dispute skill, users are likely to paste real claimant information, increasing the risk of unnecessary collection, retention, or disclosure of personal data.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
90% confidence
Finding
Using the single short trigger '拒赔' creates a high likelihood of accidental matching in unrelated or preliminary conversations, because the term is common in insurance discussions and lacks intent specificity. While this overlaps with the broader trigger issue, the risk remains distinct at the individual trigger level because it can cause premature activation of a workflow that requests sensitive materials.

Static analysis

No suspicious patterns detected.