Back to skill

Security audit

Insurance Agent Trainer

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed insurance training-content framework with no executable artifact or hidden data movement, but its document-upload parsing claims should be clarified.

Install only with the understanding that this is a training-content framework, not a verified insurance compliance system or document-processing implementation. Do not provide real customer PII or sensitive business data unless your organization has approved local handling controls, and have licensed insurance or compliance staff review generated scripts, product comparisons, and regulatory claims before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The workflow claims the skill will parse uploaded product documents and generate outputs from them, while earlier sections explicitly state parsing is only conceptual and that no actual PDF/OCR/document extraction occurs. This inconsistency can mislead users or downstream agents into treating the skill as authorized to process uploads, creating unsafe assumptions about data handling, capability boundaries, and compliance review.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The architecture and I/O sections describe a Product Doc Parser handling PDF/Word/Images and document upload inputs as if these are real operational features, contradicting repeated disclaimers that such parsing is only conceptual. In a skill that may be used with sensitive insurance and customer-related materials, capability confusion increases the risk of unauthorized document handling, accidental PII exposure, and incorrect trust by operators.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.