Back to skill

Security audit

Insurance Solvency Reporter

Security checks across malware telemetry and agentic risk

Overview

This appears to be a specialized C-ROSS insurance solvency reporting skill that asks for relevant financial inputs but does not show evidence of hidden execution, persistence, or data exfiltration.

Install only if you intend to use it for C-ROSS or similar insurance solvency reporting work. Treat company financial, capital, risk, and regulatory inputs as confidential: redact unnecessary details, avoid personal data and secrets, and confirm you are authorized before pasting internal reporting materials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list is very broad and includes generic finance, regulation, and reporting terms without clear scope limits or activation criteria. This can cause the skill to activate in unrelated conversations and solicit or process sensitive insurance solvency, capital, or compliance data when the user did not explicitly intend to use this specialized skill.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow explicitly expects users to provide company solvency data and quarterly reporting inputs, which are likely to include non-public financial, capital adequacy, risk, and regulatory information, but there is no warning or handling guidance. Without a sensitivity notice, users may overshare confidential corporate data, increasing the risk of privacy, confidentiality, and compliance violations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.