Back to skill

Security audit

Claim Expert Digital Employee

Security checks across malware telemetry and agentic risk

Overview

The skill is a claims-workflow assistant, but it asks for broader operational access, credentials, notifications, case closure, and long-term logging than its safety notice discloses.

Review before installing. This skill may be useful only in a controlled insurance-operations environment with approved MCP tools, secure secret management, explicit human approval for case registration, notification, closure, and archival actions, and a documented logging/retention policy. Do not paste live API keys into chat, and do not enable broad customer, medical, or claims-system access unless those permissions are intentionally granted and monitored.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill explicitly claims it has no persistent storage, network calls, background execution, or credential collection, yet later instructs operational writes, notifications, archival actions, and external system orchestration. This mismatch can mislead operators and reviewers into granting trust or permissions under false assumptions, increasing the chance of unauthorized data handling and transactional actions in a high-sensitivity insurance workflow.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The document says it does not provide insurance advice, but multiple modules instruct substantive claims decisions such as liability review, fraud scoring, payout calculation orchestration, and claim closure. This contradiction creates governance and compliance risk because users may rely on outputs that are functionally adjudicative while the skill disclaims responsibility.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The material analysis module asks for and uses an API key even though the skill states it does not collect credentials. Requesting secrets through natural-language workflow instructions is dangerous because users may paste live credentials into chat or logs, exposing them to the model, transcripts, or downstream retention systems.

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The module claims personal identity data is only used for the current review and not persistently stored, but also mandates detailed audit logging and multi-year retention. In a claims context this creates a direct privacy and data-governance contradiction that can result in over-retention of sensitive medical and identity information.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The declared allowed tools and capabilities present the skill as analysis/reference-only, but the body defines broad transactional claims operations and orchestration across multiple external systems. This can bypass capability review and least-privilege expectations, especially where the skill handles claim registration, notification, closure, and archival steps.

Ssd 3

Medium
Confidence
92% confidence
Finding
The instructions require collecting and retaining detailed user/customer inputs, identifiers, decision points, and outputs in audit logs. In a claims workflow this creates natural-language leakage and over-collection risk because highly sensitive medical, identity, and financial case data may be preserved unnecessarily or exposed to broader audiences than needed.

Ssd 3

High
Confidence
99% confidence
Finding
The module explicitly asks the user to provide an API key in natural language. This is a direct credential-collection anti-pattern because secrets supplied in chat can be stored in transcripts, echoed in outputs, or included in audit artifacts, leading to account compromise or unauthorized API usage.

Ssd 3

Medium
Confidence
91% confidence
Finding
The skill pairs long-term audit retention with detailed execution records including operator info, input hashes, model usage, outputs, and confidence data. In this domain such logs can become a secondary repository of sensitive claims information, increasing breach impact and regulatory exposure if retention and minimization are not tightly controlled.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.