Back to skill

Security audit

Underwriting Expert Digital Employee

Security checks across malware telemetry and agentic risk

Overview

The skill is a plausible insurance-underwriting workflow, but it under-discloses live customer contact, external system use, and sensitive audit logging.

Review this skill before installing. Use it only in an environment where the external MCP tools are intentionally authorized, live outreach requires explicit human approval, customer recipients are confirmed, and audit logs are redacted with clear retention limits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The top-level skill presents itself as a knowledge/reference underwriting assistant, but Module 4 adds operational customer outreach behavior including phone calls and messaging. This materially expands the trust boundary from analysis to real-world external actions, increasing the risk of unauthorized contact, social engineering, or accidental customer impact if the skill is activated unexpectedly.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The skill defines direct outbound calling and message-sending actions even though the declared allowed-tools/capabilities do not justify such external operations. This mismatch can cause reviewers or orchestration systems to under-estimate the skill's power, enabling unapproved real-world actions against customers.

Context-Inappropriate Capability

Medium
Confidence
85% confidence
Finding
The skill claims to be a reference framework with no persistent or external operational behavior, yet Module 3 includes notification generation and integration with a notification system. Even if framed as document generation, this introduces external workflow effects that contradict the safety posture and can be used to produce or dispatch formal customer-facing underwriting notices.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The file states there are no network calls, but later modules define extensive MCP and external system invocations for OCR, ASR, CRM, underwriting, notification, telephony, and messaging. This is a significant integrity issue because the skill's declared trust model is materially weaker than its actual ability to transmit data to outside systems.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The file states there are no network calls, but later modules define extensive MCP and external system invocations for OCR, ASR, CRM, underwriting, notification, telephony, and messaging. This is a significant integrity issue because the skill's declared trust model is materially weaker than its actual ability to transmit data to outside systems.

Vague Triggers

Medium
Confidence
83% confidence
Finding
Module 1 uses broad trigger phrases such as general underwriting and risk terms, which can cause unintended activation during ordinary discussion. In a skill handling health, financial, and underwriting data, over-broad activation increases the chance of collecting unnecessary sensitive information or initiating analysis without clear user intent.

Vague Triggers

Medium
Confidence
82% confidence
Finding
Module 2's trigger phrases are broad and overlap with common medical or insurance discussions, creating a risk of accidental activation. Because this module performs deep medical-underwriting analysis, unintended entry can lead to over-collection of health data and unsupported workflow escalation.

Vague Triggers

Medium
Confidence
80% confidence
Finding
Module 3 trigger phrases are generic enough to match ordinary conversation about explanations or notices. That can unintentionally start customer-facing document generation for underwriting outcomes, which is higher risk than passive explanation because it creates formal communications artifacts.

Vague Triggers

High
Confidence
94% confidence
Finding
Module 4 includes everyday trigger phrases like contacting a customer or sending a message, which are especially dangerous because this module performs real-world outbound actions. Loose activation for a communication-capable skill can result in unauthorized calls or messages to customers based on casual phrasing.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The module describes automatic customer contact and message sending without an upfront warning that it may perform real-world outbound actions. Users may interpret the skill as advisory only, increasing the risk of surprise external communications and consent failures.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
Module 5 enables full transcription and analysis of customer audio/video, including speaker identification and emotional analysis, but lacks a clear upfront privacy warning in the module description itself. Given the sensitivity of recorded customer conversations, insufficient notice increases legal, compliance, and privacy risk.

Ssd 3

High
Confidence
98% confidence
Finding
The audit logging requirements direct retention of full input/output snapshots, scoring records, health-disclosure review details, and underwriting conclusions. In this domain that naturally captures highly sensitive health, financial, and identity data, creating a substantial privacy and compliance exposure if logs are accessed, over-retained, or reused.

Ssd 3

Medium
Confidence
90% confidence
Finding
The follow-up module collects customer contact details, conversation transcripts, intent labels, and follow-up outcomes, and its audit instructions imply persistence of that information. This creates a natural-language sensitive data capture channel that could store personal communications and inferred intent beyond what is necessary for an underwriting reference skill.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.