Back to skill

Security audit

Baa Review

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward BAA compliance-review skill, but users should avoid submitting unnecessary PHI or identifiers.

Installers should treat uploaded or pasted BAAs as sensitive. Redact unnecessary PHI, patient identifiers, and irrelevant confidential business details when possible; if a full agreement is needed, use this only in an environment approved for that data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly invites users to paste or attach a Business Associate Agreement, which commonly contains PHI, contract metadata, contact details, and other sensitive information, but provides no warning about minimizing PHI, redacting unnecessary identifiers, or handling uploaded content securely. In a compliance-review context, this omission increases the likelihood that users will disclose regulated health information to the agent unnecessarily, creating privacy and data-handling risk even if the skill’s stated purpose is legitimate.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.