Back to skill

Security audit

Insurance Agent Digital Employee

Security checks across malware telemetry and agentic risk

Overview

The skill is a broad insurance-agent assistant, but it contains conflicting instructions about saving files, web/API use, and social-media posting while handling sensitive customer, financial, and health information.

Review before installing. Use this only in a controlled professional environment, keep network access, local file writes, social-media publishing, and logged-in browser automation disabled unless explicitly approved, and require human review before using any generated insurance, health-disclosure, marketing, or customer-facing material.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
Module 7 instructs generating audit logs to a local `audit/` directory, which contradicts the top-level claim that the skill does not write local files. Even if framed as documentation, this kind of contradictory operational guidance can cause downstream agents or integrators to enable unexpected local persistence of sensitive customer interaction data.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
Module 8 similarly directs creation of audit logs in a local directory despite repeated assurances elsewhere that the skill performs no local writes. Because Module 8 handles health disclosures, this contradiction is more sensitive: implementers may persist regulated health-related data locally without proper controls.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
Module 12 claims there is no real social-media automation, but later provides concrete auto-publishing workflow details, including publishing commands, timing behavior, local output paths, and API/tool references. This mismatch can mislead a host agent into performing real external actions, creating risks of unauthorized posting, data leakage, and policy bypass.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest and capability notice state that the skill has no persistent storage or network calls, yet later sections describe web search, local file saving, publishing workflows, and external API use. This is a trust-boundary violation: platform reviewers or orchestrators may grant the skill low-risk treatment while the body embeds instructions for higher-risk behaviors.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The skill uses broad natural-language triggers and automatic routing across many modules, increasing the chance that ordinary user conversations activate the wrong workflow. In a sensitive insurance context, misrouting can cause collection or processing of personal, financial, or health information beyond the user's intended scope.

Vague Triggers

Medium
Confidence
80% confidence
Finding
Module 2's trigger phrases such as customer consultation, needs analysis, initial communication, and risk assessment are ambiguous and likely to overlap with common insurance conversations. This can over-activate a workflow designed to probe for family structure, income, assets, and health-related details, creating unnecessary data exposure.

Vague Triggers

Medium
Confidence
79% confidence
Finding
Module 3 is activated by generic phrases like insurance analysis, policy diagnosis, and planning suggestions, which are broad enough to match many benign requests. In practice, this may trigger detailed gap analysis and financial inference using sensitive household and income information without clear user consent to that specific processing.

Vague Triggers

Medium
Confidence
79% confidence
Finding
Module 4's triggers for plan, insurance proposal, or protection planning are broad and may collide with ordinary requests for generic information. Because this module can produce formal plan documents containing customer, agent, and product details, accidental activation could lead to over-collection or generation of quasi-official documents without proper review.

Vague Triggers

Medium
Confidence
76% confidence
Finding
Module 6 can be activated by vague terms like product knowledge base, script recommendation, or simulation drill, yet it includes document ingestion, knowledge extraction, and script generation behaviors. Broad activation increases the risk of unintentional processing of uploaded product materials or generation of compliance-sensitive sales content.

Vague Triggers

Medium
Confidence
83% confidence
Finding
Module 12's trigger list includes broad marketing-related phrases that can unintentionally activate a workflow tied to content generation, publishing guidance, and lead tracking. Given the module's conflicting operational instructions, accidental activation here is more dangerous because it may steer an agent toward external-platform or lead-management behaviors.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.