Chiropractic Practice Marketing Kit

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only healthcare marketing skill with coherent compliance-focused behavior, but users should verify the realistic provider examples before reusing them.

Before installing or using this skill, treat the sample practice, doctors, addresses, license numbers, and credential IDs as unverified. Replace them with placeholders or verified client-approved details, and have legal/compliance staff review generated healthcare marketing before publication.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The README markets the skill as enforcing HIPAA-safe marketing practices, yet the worked example includes specific provider names, location, and credential identifiers that appear realistic rather than clearly fictional placeholders. If these correspond to real individuals or are reused as templates, the skill could expose personally identifiable or professional data and undermine its own privacy/compliance claims, increasing the risk of unauthorized disclosure or deceptive safety assurances.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal