Back to skill

Security audit

保险条款可视化图谱

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent insurance-policy visualization helper, with a privacy caution because users may paste sensitive policy details.

Before using it, redact policy numbers, names, addresses, claim history, medical details, and other identifiers unless they are necessary for the visualization. The inspected artifacts do not show external transmission or persistence, but pasted content will still be processed by the agent environment running the skill.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly asks users to paste full insurance contract text, which can easily include policy numbers, names, addresses, claim history, beneficiaries, and other sensitive personal or financial data. Because the skill is designed to transform this content into generated HTML without any warning, minimization guidance, or redaction instructions, users may disclose more sensitive information than necessary.

Static analysis

No suspicious patterns detected.