Back to skill

Security audit

Health Ai Applications

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a coherent health-industry workflow reference, but it tells the agent to automatically install and load another skill and gives under-scoped guidance around customer and business data.

Review this before installing if you do not want skills to add other skills automatically. Use it only with explicit approval for installing Universal Task OS, and avoid entering real customer names, order data, health information, credentials, or confidential business details unless your organization has approved privacy, retention, access-control, and human-review processes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to automatically install and load another skill at activation time, expanding capabilities without explicit user approval. In a skill file, cross-skill installation is dangerous because it can silently change the execution environment, introduce unreviewed instructions, and create a supply-chain style trust boundary violation.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The dependency installation flow provides no warning, confirmation, or informed consent before attempting to install Universal Task OS. This is risky because users may believe they are invoking a passive health-AI reference skill, while the skill silently acquires additional code/instructions and permissions, increasing exposure to unintended actions or malicious downstream behavior.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The template operationalizes automated handling of refunds, shipping inquiries, complaint triage, customer-tier routing, and confidence-threshold-based decisions using real customer names, order status, and logistics data, but it does not include privacy, consent, human-review, or transparency safeguards. In a health-related customer support context, this increases the risk of exposing personal/order data, making opaque automated decisions, and giving users responses that materially affect refunds or complaint handling without adequate notice or oversight.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The phrase “执行协议等待指令” acts like a standing activation or control instruction embedded in reference content, but it lacks any narrow trigger condition, scoping rule, or boundary between descriptive text and executable agent behavior. In an agent skill, repeated broad protocol language can cause unintended prompt routing or over-application of this behavior when the file is consumed as instructions rather than as inert documentation.

Vague Triggers

Medium
Confidence
93% confidence
Finding
This repeated activation-style instruction again presents operational behavior as if the model should wait for commands and then generate outputs from listed elements. Because the phrase is broad and reused across domains, it increases the chance that a downstream agent treats the catalog as authoritative runtime instructions rather than static reference material.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The embedded instruction is functionally similar to a reusable prompt macro with no clear trigger boundary, which can be interpreted too broadly by agents ingesting the file. In a multi-step healthcare-oriented skill, this kind of ambiguous protocol text can influence outputs across tasks without an explicit user request.

Vague Triggers

Medium
Confidence
93% confidence
Finding
This line continues the pattern of imperative activation text embedded in a task catalog, creating ambiguity about whether the content is descriptive or operational. Such ambiguity is risky because agents may generalize the instruction and automatically generate regulated packaging-related content without appropriate checks or intent confirmation.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The repeated broad activation phrase can steer the agent into following an implicit execution protocol whenever this domain is referenced. Because the file spans advertising and promotional materials, unclear activation increases the risk of unintended content generation in areas already subject to legal and platform restrictions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The website optimization section includes the same protocol-style language, which may cause an agent to treat SEO and technical tasks as default actions once the file is loaded. Overly broad instruction text in reference documents can produce unintended autonomous behavior or priority conflicts with higher-level safeguards.

Vague Triggers

Medium
Confidence
92% confidence
Finding
This business-management section again embeds a generic execution protocol with no clear invocation boundary. In agent environments, repeated protocol text can create prompt-injection-like control bleed, where generic planning behavior is applied even when unrelated or when stricter governing instructions should take precedence.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The same broad activation phrase appears in the after-sales auto-reply section, but here the risk is higher because it touches customer interactions, intent classification, and automated routing. Ambiguous protocol text could cause an agent to auto-generate or auto-apply customer-service behaviors without sufficient oversight, increasing the chance of harmful, incorrect, or privacy-impacting responses.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The training/courseware section repeats the same broad instruction pattern, again blurring the line between a reference checklist and an executable prompt. In a health-related context, this could contribute to uncontrolled generation of educational material that appears structured and authoritative without adequate evidence or compliance confirmation.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This section describes linking customer level and order status with CRM data for differentiated handling, but it provides no privacy notice, data minimization guidance, access control requirement, or legal basis reminder. In a health-industry skill, combining service interactions with customer and order metadata can expose sensitive personal or health-adjacent information and enable inappropriate profiling or unauthorized use.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The user data flow explicitly describes collecting website behavior data and feeding it into customer service and personalization, but it omits any warning about consent, transparency, retention, or cross-system privacy impact. Because the skill targets the health sector, behavioral data may reveal sensitive interests or conditions, making silent collection and reuse materially more dangerous than in a generic marketing context.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The questionnaire explicitly solicits detailed company, staffing, tooling, workflow, operational, and potentially compliance-related information, then states it will be processed by an LLM to generate a customized plan, but provides no warning about sensitivity, minimization, retention, sharing, or privacy handling. This creates a real risk of oversharing confidential business information and, in a health-sector context, could also encourage inclusion of regulated or sensitive operational details that should not be sent to an AI system without clear safeguards.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.