Back to skill

Security audit

Home Food Planner

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward meal-planning reference with no executable code, hidden data access, or privileged behavior.

Users should treat nutrition outputs as general planning help, especially for allergies or medical diets, and confirm important dietary advice with an appropriate professional. The skill appears safe to install from a security standpoint, though its routing and locale defaults may feel broad or China-centered.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is written with very broad activation conditions such as general meal planning, groceries, nutrition, and recipe help, which can cause the agent to invoke this skill for many ordinary food-related queries. Overbroad routing is dangerous because it increases the chance of unintended skill activation, unnecessary data exposure to the skill, and suppression of a more appropriate or safer skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example commands include highly generic phrases like 'Recommend dinner' and 'What do I need to buy,' which are common in everyday conversation and may match user intent too loosely. This can lead to accidental activation on ambiguous requests, causing the skill to receive context it does not need and potentially steering the conversation away from the user's intended workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description is written entirely in Chinese and gives no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. This creates a natural-language locale constraint that may conflict with organizational language-choice expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The usage example defaults to Chinese cuisine and prices in yuan, and the document heavily centers one regional food context without noting that this is optional or configurable. While not severe, this can amount to a locale assumption rather than offering a user choice or documenting the regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The package description is written only in Chinese ("家庭膳食规划工具"), which indicates a language-specific presentation without any accompanying user choice or documented regional justification in this file. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.