Back to skill

Security audit

Recipe Chef

Security checks across malware telemetry and agentic risk

Overview

This cooking skill is coherent and not malicious, but it can quietly save personal food, nutrition, household, and child-related preferences for future use without clear consent controls.

Install only if you are comfortable with the assistant remembering stable cooking preferences across sessions. Avoid saving sensitive medical, allergy, child, or household details unless needed, and review or clear remembered preferences where your agent supports it.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill description is broadly framed around common cooking requests without clear scope boundaries, which can cause over-triggering on everyday meal-related prompts. That increases the chance the skill is invoked when the user did not intend recipe discovery behavior, potentially causing unnecessary web access, image analysis, or memory-related actions in contexts that should remain simple chat responses.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The surprise-mode trigger phrases such as 'what should I cook' and 'give me dinner ideas' are very broad and lack disambiguation or exclusion rules. In practice, this can make the skill activate too aggressively for routine conversation, expanding data use or tool usage beyond what is necessary and increasing the surface for unintended behavior.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill directs automatic capture of durable food and kitchen preferences into memory whenever the session supports it, but does not require explicit user notice or consent at the point of persistence. This creates a privacy risk because users may disclose dietary restrictions, family details, health goals, or child-related preferences in a conversational context without realizing those details will be stored and reused later.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The document explicitly instructs the agent to retain durable user food, nutrition, and household-related preferences for future sessions, but it provides no privacy notice, consent check, retention boundary, or sensitivity filter. In this skill context, remembered data such as nutrition goals, child-related constraints, and household/kitchen details can reveal personal or family information, so silent persistence increases privacy and profiling risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.