Ai Insurance Advisor

Security checks across malware telemetry and agentic risk

Overview

The skill appears to use packaged reference materials for its stated guidance purpose, with no evidence of hidden execution, credential handling, persistence, or destructive behavior.

Before installing, confirm the skill only needs its packaged reference files and does not request broader filesystem access in your runtime. The current evidence supports normal, purpose-aligned use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill instructs the agent to read local reference files such as `references/products.json`, `references/insurance-knowledge.md`, and `references/compliance.md`, but no corresponding permission declaration is present. This creates a capability/permission mismatch: in permissive runtimes the skill may access local files without explicit review, while in stricter runtimes it may fail unpredictably, undermining security review and least-privilege controls.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal