Back to skill

Security audit

Gousto Recipes

Security checks across malware telemetry and agentic risk

Overview

This skill searches and fetches public Gousto recipes, with a minor documentation mismatch but no evidence of hidden data access or unsafe behavior.

Install if you are comfortable with the skill contacting Gousto's public API and storing a local recipe cache. The publisher should correct the vfjr.dev note so the documented network path is consistent with the scripts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The documentation presents the skill as using the official Gousto API, but a note says recipe fetches require a vfjr.dev proxy, introducing an undisclosed third-party network dependency. This is dangerous because recipe contents and user requests may transit through an untrusted intermediary, creating risks of data tampering, tracking, or unexpected content injection that users would not anticipate from the official-API claim.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.