Bakery

Security checks across malware telemetry and agentic risk

Overview

This is a simple bakery-shopping guidance skill with no code, install scripts, credentials, persistence, or automatic purchasing authority.

Safe to install for bakery-shopping help. Because it discusses discounts, delivery, and orders, avoid sharing payment details or precise delivery information unless you intentionally need to and trust the environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example trigger phrases are extremely broad and overlap with ordinary user questions, which can cause accidental invocation outside the intended bakery-shopping context. Unintended activation can route unrelated user prompts into this skill, increasing the risk of incorrect handling, privacy over-collection, or confusing task takeover in multi-skill environments.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal