Back to skill

Security audit

Cn Diet Tracker

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Chinese diet-tracking skill that stores user-entered meal data locally, with no evidence of hidden network access, privilege escalation, or deceptive behavior.

Use this if you are comfortable with a Chinese-language CLI saving meal, calorie, category, note, and target data locally at ~/.qclaw/workspace/diet.json. On shared systems, protect or remove that file when needed because food logs can be sensitive personal data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documents behavior that reads and writes a local JSON file, but it does not declare any explicit tool scope or permissions. That creates an authorization/transparency gap: an agent or user may invoke file operations without clear, reviewable limits, increasing the risk of unintended local data access or persistence.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The name and description explicitly position the skill as Chinese-language only (中文饮食记录) and all usage examples are in Chinese, but there is no opt-in, alternative language support, or justification for the locale constraint. This can violate language/locale policy when a skill forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring explicitly labels the skill as a Chinese diet tracker, and the command-line descriptions and output strings throughout the file are only in Chinese. This imposes a language choice on users without offering any locale or language opt-in, which matches the policy's language/locale violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill states that dietary data is stored in ~/.qclaw/workspace/diet.json but does not clearly warn users that potentially sensitive health-related entries will persist on disk in their home directory. This can lead to unintentional retention of personal data, especially on shared systems or where users expect transient processing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.