Back to skill

Security audit

Insurance Agent Digital Employee

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable insurance-agent workflow guide with sensitive-data and compliance risks that are disclosed and bounded by human review, desensitization, and no tool permissions.

Install only if you want an insurance-agent workflow reference and can enforce the stated controls: confirm the module before sharing data, enter only minimized or desensitized customer information, verify product and underwriting details in official institution systems, and have a licensed/authorized person review anything before sending, filing, or using it with customers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Broad natural-language routing at the top level can cause the skill to activate on ordinary insurance-related conversation before the user's precise intent is established. In this skill, accidental activation matters because downstream modules handle sensitive personal, financial, and health information, so ambiguous triggering increases the chance of collecting or discussing regulated data in the wrong workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example trigger phrase is overly generic and can collide with routine conversation, making unintentional routing likely. Because this skill covers profiling, financial planning, and health-disclosure workflows, mistaken routing may prompt unnecessary collection of sensitive customer data or produce advice under the wrong compliance boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Module 2 uses ambiguous triggers like customer consultation, needs analysis, and risk assessment without sufficient narrowing to a specific insurance workflow stage. This can misroute users into a consultative flow that solicits family, income, and health-related data even when they intended a different or more limited task.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Module 3 trigger terms such as protection gap, insurance analysis, and planning are broad enough to match many ordinary conversations, making false activation plausible. In context, false activation can lead to premature budget calculations, financial profiling, and plan-oriented outputs that users may over-trust as personalized insurance recommendations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Module 4 trigger phrases like plan book, insurance plan, or protection planning are not distinct enough from adjacent modules such as needs analysis or gap assessment. In a workflow that can generate formal-looking plan documents, accidental activation raises the risk of producing quasi-official proposal materials before prerequisite review, data validation, or compliance checks are completed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The health-disclosure module states that it does not predict underwriting outcomes, yet the output template still includes concrete example wording such as possible surcharge/exclusion/delay outcomes for specific conditions. In an insurance sales context, users may treat these examples as quasi-official risk predictions, which can mislead customers, bias disclosure conversations, and create compliance exposure around unauthorized underwriting guidance.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

L1927-L1933将 product-system 和 underwriting-system 标为“必需”,表明模块依赖外部系统规则查询;但紧接着L1934-L1938又写“无机构系统能力依赖,本技能可直接基于知识库运行”。这不是单纯信息不全,而是对模块是否依赖外部系统给出相反表述,容易误导使用者对实际能力边界的理解。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.