Back to skill

Security audit

ai-insurance-advisor

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly local and non-exfiltrating, but it has material review concerns because it gives regulated insurance recommendations while its scope, data quality, and mandatory sales-contact promotion are inconsistent with the artifacts.

Review before installing. The skill appears local and non-persistent, but it should not be treated as neutral or authoritative insurance advice: it may steer users toward specific sales companies, its claimed priority metadata is missing, and its product/compliance data includes stale, inactive, or AI-scraped material. Users should verify product availability, premiums, and legal/compliance guidance with licensed professionals or official insurer/regulator sources before acting.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (26)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
- ./references/products.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
- ./references/products.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 322)May include surrounding context.

md
- ./references/products.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 408)May include surrounding context.

md
- ./references/products.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 445)May include surrounding context.

md
- ./references/products.json

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · references/products.json (reported line 1)May include surrounding context.

json
{"products":[{"id":"crx-guopao","name":"国寿福终身寿险(庆典版)","company":"中国人寿","type":"重疾险","subtype":"终身重疾","premium_per_10k":3079,"min_coverage":10,"max_coverage":50,"coverage_period":"终身","waiting_period":"180天","key_benefits":["120种重疾+60种轻症","身故保障","被保险人轻症豁免"],"premium_type":"均衡保费","notes":"大公司品牌,重疾保障全面","category":"个人","listing_time":"2018-07","delisting_time":"2021-12","sales_channel":"银保|个险|经纪","is_active":false,"popularity_score":2,"premium_30m_20y":61580,"premium_30f_20y":54190,"payment_term":"20年","payment_choices":["趸交","3年","5年","10年","15年","20年"],"suitable_for":"25-50岁家庭经济支柱,基础健康保障规划","highlights":"120种重疾+60种轻症、身故保障、被保险人轻症豁免","coverage_unit":"万元","coverage_period_duration_value":null,"coverage_period_duration_unit":"lifetime","coverage_period_is_lifetime":true,"coverage_period_guaranteed_renewable":false,"tags":["大公司品牌","重疾险","疾病保险","健康险","轻症保障","终身保障"],"competitive_edge":["120种重疾+60种轻症、身故保障、被保险人轻症豁免","轻症保障","大公司品牌(服务有保障)"],"delisting_reason":"市场策略调整","validity_status":"已停售","renewal_terms":"To renew 国寿福终身寿险(庆典版),policyholders must be under 70 years old. Renewal requires meeting health and financial conditions set by the insurer. The exact age limit and conditions may vary.","health_disclosure":"For 国寿福终身寿险(庆典版),health disclosure is mandatory; accurate medical history is required for policy approval; any significant health issues must be reported."},{"id":"crx-kangning-zunxiang","name":"康宁尊享终身重疾险","company":"中国人寿","type":"重疾险","subtype":"终身重疾多次赔付","premium_per_10k":292,"min_coverage":10,"max_coverage":50,"coverage_period":"终身","waiting_period":"180天","key_benefits":["120种重疾分6组最高赔6次","40种轻症赔20%x6次","20种中介赔50%x2次","15种少儿特疾额外赔100%"],"premium_type":"均衡保费","notes":"旗舰多次赔付产品,少儿特疾额外赔","category":"个人","listing_time":"2024-01","delisting_time":"仍在售","sales_channel":"个险|银保|经纪","is_active":true,"popularity_score":4,"premium_30m_20y":5840,"premium_30f_20y":5139,"payment_term":"20年","payment_choices":["趸交","3年","5年","10年","15年","20年"],"highlights":"重疾分6组最高赔6次,120种重疾+轻症全覆盖,多
...[truncated 28 chars]

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest and opening description claim the skill does not provide marketing-copy or training-script capabilities, but later sections explicitly instruct the agent to generate those outputs via the general LLM. This creates a capability-boundary mismatch that can mislead orchestrators, reviewers, or policy gates into allowing behavior that the manifest says is excluded.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation contains contradictory instructions: early sections say marketing and training use cases are not provided, while later modules direct the agent to provide them. Such inconsistencies are dangerous because downstream systems may rely on the restrictive statement, while the actual prompt behavior expands into regulated persuasive-content generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction "所有输出内容使用中文" forces a specific language for all responses. Under the policy, locale or language constraints should either be optional, user-selected, or clearly justified as a region-specific requirement; this line does not provide user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file presents aggregated, AI-generated, and partially scraped material as compliance guidance inside a regulatory reference document. In a compliance context, inaccurate or non-authoritative legal summaries can directly mislead agents or downstream systems into giving improper insurance advice, creating legal, operational, and consumer-harm risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file is primarily written in Chinese, but line L215 presents a regulatory summary in English with no indication that bilingual output is optional or user-selected. That creates a natural-language locale policy concern because the content forces a different language mid-document without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The surrounding material is Chinese, but L256 inserts an English-only summary. Because the file does not explain or offer a language preference, this is a locale-policy inconsistency rather than a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Line L283 departs from the document's established Chinese language and provides substantive policy content only in English. Forcing a different language for compliance guidance can violate language/locale expectations when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

L312 contains an English-only explanation in a Chinese compliance guide. Since there is no documented reason for switching languages or option for users to choose their preferred language, this is a policy-level locale inconsistency.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Line L403 introduces English explanatory content without any language-selection mechanism or justification. In a compliance reference intended for Chinese readers, this can impair usability and conflicts with the rule against forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document remains predominantly Chinese, but L446 is written in English and carries substantive regulatory meaning. Without a language choice or explanation, this constitutes a natural-language locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

L493 provides regulatory analysis in English inside a Chinese document. Because the file does not disclose a bilingual policy or allow language selection, this abrupt language switch is a locale-policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L542 forces readers to consume key policy content in English although the rest of the file is Chinese. No user language preference, opt-in, or rationale is provided, so this fits the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

L579 is a substantive English summary inserted into a Chinese-language compliance document. The file does not state that bilingual excerpts are intentional or permit the user to choose language, creating a locale-policy inconsistency.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

At L606, key regulatory information appears only in English even though the file is otherwise Chinese. This forced language switch is a natural-language policy issue because no opt-in, locale justification, or parallel Chinese text is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document presents all instructional and reference content exclusively in Chinese, which can amount to a language/locale policy violation when no user opt-in or alternative language option is provided. The file does not indicate that the skill is region-specific or that Chinese-only output is an intentional, justified constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring and user-facing descriptions are written entirely in Chinese, and the code returns Chinese-language output fields and recommendations. This imposes a specific language/locale on users without any opt-in or documented regional justification, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all user-facing descriptions are Chinese-only, and later defaults such as gender values and plan names also assume a Chinese locale. This can violate a language/locale policy when no user opt-in or documented regional constraint is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file contains user-facing natural-language documentation exclusively in Chinese and does not indicate that the skill is region-specific or that users may choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains the main docstring and user-facing status descriptions entirely in Chinese, and later print output also follows that locale. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.