Back to skill

Security audit

MenuVision

Security checks for vulnerabilities and agentic risk

Overview

MenuVision is mostly a coherent menu-building skill, but it needs review because optional GitHub publishing uses a PAT insecurely and URL fetching is not scoped to public restaurant sites.

Install only if you are comfortable with menu content, page screenshots, and generated prompts being sent to Gemini. Avoid using the optional GitHub publishing flow unless you restrict the token to one repository, confirm the destination repo, and replace URL-embedded PAT authentication with a safer credential method. Run URL extraction in a constrained environment and do not feed it untrusted or internal URLs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:540
Finding

Unrestricted URL Fetching Enables SSRF and External Disclosure of Retrieved Content

Content
View full analysis
= 0.02): Clean HTML, send text to Gemini 2.5 Flash (JSON mode) 5. **JS-rendered** (density < 0.02, e.g. Wix, Framer): Screenshot with Playwright, send to Gemini Vision 6. **Screenshot height cap**: If screenshot > 6000px tall, resize proportionally to fit 7. **Large menus** (>12k chars text): Chunked extraction, merge like PDF multi-page. ``` ### Technical Analysis The Skill instructs generated code to fetch a user-supplied restaurant URL using `requests`, with Playwright as a fallback for pages classified as JavaScript-rendered. It does not require validation of the URL scheme, resolved IP address, redirects, destination port, or final response URL. Consequently, an attacker may supply a URL targeting a resource accessible from the execution environment but not from the public Internet. Potential targets include: - Loopback services such as `127.0.0.1` or `::1` - Private network services - Link-local resources and cloud instance metadata - Services reached through DNS rebinding - Public URLs that redirect to prohibited internal destinations The fetched response is then cleaned and sent to Gemini as text, or rendered and sent as a screenshot. This creates an SSRF-to-disclosure chain: content retrieved from an internal destination may be transmitted to an external API. Fetching restaurant pages is necessary for the declared functionality, but unrestricted network access exceeds minimum privilege. Access should be constra ...[truncated 1318 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:693
Finding

GitHub Personal Access Token Is Embedded in a Git Remote URL

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:664
Finding

Unpinned Python Packages and Browser Binary Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill includes code-path guidance for cloning a repository, copying generated files, and pushing content to GitHub using a personal access token. Even if intended for convenience, this adds outbound authenticated write access unrelated to the core extraction task, creating risk of unintended publication, misuse of supplied GitHub credentials, or modification of repositories if the workflow is triggered without strong user confirmation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata and top-level description frame the capability as menu extraction and HTML generation, but the documented pipeline also includes an optional publishing stage to GitHub Pages. This is a real scope-expansion issue because it introduces a separate remote-write capability that users and reviewers may not expect from the manifest alone, increasing the chance of over-privileged execution or accidental data publication.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.