Back to skill

Security audit

Dining

Security checks for vulnerabilities and agentic risk

Overview

This is a dining recommendation skill with disclosed, purpose-aligned behavior, though users should be aware of its unpinned install command and optional preference profile memory.

Before installing, prefer a pinned release or reviewed commit instead of the unpinned npx command. If you use the memory/profile feature, avoid saving sensitive medical details unless you are comfortable pasting that profile into future sessions, and treat the skill's health-related meal suggestions as dietary guidance rather than medical advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README_EN.md:85
Finding

Unpinned Third-Party Package Execution During Installation

Content
View full analysis
Remediation
View remediation
add ChenChen913/dining-skill ``` 2. Document the expected package version, source, and integrity information so users can verify the downloaded artifact before execution. 3. Prefer an installation method that checks out a specific immutable commit or signed release rather than the repository's moving default branch: ```bash git clone https://github.com/ChenChen913/dining-skill.git cd dining-skill git checkout ``` 4. Where supported, use package-manager lockfiles, registry integrity hashes, provenance attestations, and signature verification. 5. Review the installer package and its transitive dependencies before designating the command as the recommended installation method. 6. Advise users not to run the installation command with `sudo`, as an administrator, or from an account with unnecessary privileges. 7. Apply the same corrected instructions to both `README.md` and `README_EN.md` to keep the documented installation paths consistent. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx skills add ChenChen913/dining-skill without pinning an exact package version. This can cause users to execute whatever package is current at install time, increasing supply-chain risk if the package is updated maliciously, compromised, or changed incompatibly. The fact that this is an installation command in a skill repository makes it more dangerous because users may copy-paste it directly and execute remote code locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is written entirely in Chinese and frames the skill as a Chinese dining-decision assistant without offering any language choice or opt-in. Under the language/locale policy rule, this is a natural-language policy concern because it may implicitly force a specific language for users who did not request it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains user-facing guidance exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into another language. Under the language/locale policy, forcing a specific language without user choice can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file is entirely written in Chinese and defines user-facing behavior without any mechanism to detect or honor the user's preferred language. This can cause the skill to respond in an unexpected language, degrading usability and potentially causing misunderstanding of dietary constraints, allergies, or health-related preferences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill file is written as Chinese-only operational guidance, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language or China-specific environment. This can violate language/locale policy when a skill implicitly enforces one language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document title and all operational instructions are written in Chinese, indicating the skill behavior and output conventions are constrained to Chinese by default. There is no visible note offering multilingual support, user language selection, or justification that this is a region-specific tool, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section instructs the system to infer and retain sensitive personal data, including health conditions, dietary restrictions, allergies, and regional background, and to package that data into a reusable profile for future sessions. Although the design relies on user-pasted memory rather than hidden persistent storage, it still normalizes collection and reuse of sensitive profile data without an explicit privacy notice, minimization guidance, or clear consent checkpoint, creating a real privacy and profiling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The feedback loop asks users to share opinions and explicitly says '我会记住', but it does not clearly warn that this feedback will be logged, structured, and reused to influence future recommendations. Because the surrounding design converts casual feedback into remembered preference weights, users may disclose information without understanding that it will become part of a continuing profile.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

该文件的自然语言内容完全以中文编写,并以中文短语定义触发与路由规则,但未说明是否支持其他语言或允许用户选择语言。按 SQP-3,若技能在自然语言层面隐含强制特定语言/locale 且无用户 opt-in,属于语言/地区策略风险。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

该 markdown 文件属于 SQP-1 适用范围,表格中的多个触发信号如“随便吃点”“好好做一顿”“换换口味”“单人”等都与日常表达高度重叠,缺少明确边界,容易在普通对话中被匹配为模式切换信号。文档虽列出示例,但没有给出排除条件或负例,难以区分何时应触发、何时不应触发。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

“若无法判定,默认 Efficiency(快速通道)或 Social(慢速通道)”没有说明两者如何区分,也未给出具体判定条件,属于激活条件不清晰。此类默认分流会在信号不足时引入不确定路由,增加技能被意外归入某一模式的风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The schema hardcodes Chinese-only interaction and output conventions without any mechanism to detect, preserve, or ask for the user's preferred language. This can cause accessibility, usability, and consent problems for users who communicate in other languages, and may lead to misunderstandings around dietary restrictions, allergies, or health constraints in a food-planning context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that the skill can remember user taste preferences over time but provides no notice about what data is stored, how long it is retained, or how a user can delete or opt out. While the stored data appears limited to food preferences, it can still reveal health-related restrictions, cultural background, or lifestyle patterns, making this a real privacy weakness. In a dining-planning skill this is less dangerous than in a medical or finance context, but the mention of allergies, fitness goals, and dietary constraints increases sensitivity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

All headings, examples, trigger phrases, and user-facing text are exclusively in Chinese, and the documented interaction patterns assume Chinese-language input and output. Under the language-policy rule, forcing a specific language without opt-in or justification can be a policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.