Back to skill

Security audit

UAE Clinic Arabic Comms

Security checks across malware telemetry and agentic risk

Overview

This is a template-only Arabic/English clinic communication skill with no code or hidden access, but users should confirm each patient’s language preference and review medical content before use.

Safe to install as a drafting aid. Before using it with real patients, confirm the patient’s preferred written and spoken language or dialect, avoid entering unnecessary patient identifiers unless your environment is approved for health data, and have qualified clinic staff review medical or consent-related wording before sending.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill hard-codes communication language choices based on patient nationality or demographic category rather than requiring explicit patient or user preference. In a healthcare setting, this can cause inappropriate language selection, profiling, or exclusion, and may lead to privacy, consent, or comprehension failures if the assumed language is wrong.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.