Back to skill

Security audit

Tandoor Recipe CLI

Security checks across malware telemetry and agentic risk

Overview

This skill asks for sensitive Tandoor access, but its powers are disclosed, purpose-aligned, and scoped to user-approved recipe, shopping, and household tasks.

Install this only if you want an agent to access your Tandoor instance. Start with a read-only, short-lived token, review the external tandoor-cli npm package before granting write access, avoid admin or space-owner tokens unless needed, and confirm your agent actually asks before running destructive or bulk commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The document asserts that approval gates and confirmation requirements exist, but SECURITY.md itself is non-executable documentation and provides no technical control that enforces those guarantees. In an agent setting, users may rely on these claims and grant the skill write-capable tokens, creating a false sense of safety that can lead to unauthorized or destructive actions if the surrounding system does not independently implement confirmations.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The examples state that destructive prompts should trigger confirmation or refusal, but the file provides only expected behavior text and no executable validation, policy engine, or test harness that ensures an agent will behave that way. Because this skill manages recipes, shopping lists, and household/admin functions over an API, misleading validation guidance can result in real data modification or deletion when operators assume protections exist.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.