Back to skill

Security audit

Healthcare

Security checks across malware telemetry and agentic risk

Overview

This healthcare skill is instruction-only, but it covers sensitive patient records, prescriptions, lab results, billing, triage, and outbound patient communication with broad authority and limited human-approval boundaries.

Review carefully before installing in any real healthcare environment. Use only with authorized clinic accounts and approved systems, and require human review before patient messages, record access or release, prescription or refill actions, lab-result communication, billing changes, collections activity, or emergency escalation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill is scoped to broadly handle 'clinic and healthcare facility operations' without clear activation boundaries, exclusions, or user-consent conditions. In a healthcare context, overly broad invocation is dangerous because the agent may engage in scheduling, records, prescription, billing, or triage tasks inappropriately, increasing the chance of unauthorized handling of protected health information and unsafe automation of clinical workflows.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs sending reminders, refill notifications, lab-result alerts, and outreach lists but does not prominently disclose that it may contact patients or process highly sensitive medical data. In healthcare, this omission is especially risky because users may invoke the skill without realizing it can trigger external communications or access PHI, leading to privacy violations, consent failures, and noncompliant disclosure of medical information.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.