Back to skill

Security audit

买重大疾病保险不踩雷 | Critical Illness Insurance Advisor

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only critical illness insurance questionnaire that asks sensitive health and financial questions, but it is disclosed, purpose-aligned, and does not install or run code.

Install only if you are comfortable answering questions about health, family medical history, income, and debt for insurance guidance. Avoid sharing names, IDs, phone numbers, or other identifying details, and treat the output as general guidance rather than licensed medical, financial, or insurance advice.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes very broad phrases such as '买保险', '保险建议', and '保险推荐', which can cause the skill to activate in contexts beyond critical illness insurance. This can lead to unintended collection of sensitive health, family history, and financial information from users who did not intend to enter a detailed risk-assessment flow.

Static analysis

No suspicious patterns detected.