Restaurants

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a local restaurant tracker that stores notes on the user's machine, with no evidence of exfiltration or harmful behavior.

Install only if you are comfortable with the agent keeping restaurant notes and preferences in ~/restaurants/. Ask it to confirm before saving entries if you only want casual restaurant discussion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad and conversational, so the skill could activate on routine restaurant-related discussion rather than a clear request to use this skill. Because the skill can create and organize files under the user's home directory, unintended activation increases the chance of unsolicited data collection or filesystem changes.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly creates a workspace in ~/restaurants/ but does not warn the user in the description or require consent before writing to the home directory. This is risky because users may not realize the skill persists personal dining history and preferences locally, leading to unexpected storage of sensitive lifestyle data.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal