Back to skill

Security audit

Insurance Claims Intelligence

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only insurance claims advisory skill that repeatedly requires human review and does not ship executable code, persistence, credentials, or automatic claim actions.

Use this only as a claims workflow and drafting aid. Do not paste unnecessary personal or medical data, redact identifiers where possible, verify any regulatory references against current official sources, and ensure a qualified insurance professional reviews all claim decisions, payout amounts, denial language, and fraud labels before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

md
| 示例四:免责条款命中 | 事故认定书载明酒驾 | 规则8 事故性质与免责比对 | 建议拒付并出具书面拒赔通知,注明免责条款编号 | 免责条款是否已履行明确说明义务;是否存在条款解释争议 |

> **⚠️ IMPORTANT / 重要提醒**
> The liability determination output is a **decision-support suggestion ONLY**. Final approval/denial MUST be made by an authorized human reviewer. This skill does NOT auto-approve any claim amount.
> **中文:** 判责输出**仅为决策支持建议**,最终核准/拒付**必须由授权人工审核员作出**。本Skill不对任何理赔金额进行自动审批。

### 3. Anti-Fraud Assessment — Advisory Framework / 反欺诈评估(咨询框架)

Static analysis

No suspicious patterns detected.