Meals

Security checks across malware telemetry and agentic risk

Overview

This is a simple meal-planning skill that stores meal plans and shopping notes locally, with no evidence of hidden or harmful behavior.

Safe to install for personal meal planning. Before using it, be aware that it is designed to create a ~/meals/ folder and retain local notes about meals, shopping, preferences, ratings, and optional dietary needs; avoid storing information there that you do not want persisted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
92% confidence
Finding
The skill explicitly instructs creation of a `~/meals/` workspace without indicating that user consent should be obtained first. While the path and purpose are benign, silent filesystem writes violate least surprise and could create unwanted directories or files in the user's home directory.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal