今天吃什么 - 智能三餐规划引擎

Security checks across malware telemetry and agentic risk

Overview

This skill is a local meal-planning helper that only uses a dish library and a small meal-history file to avoid repeats.

Before installing, understand that the skill may run for common meal-choice questions and will keep a small local history of recommended dishes so it can avoid repeats. It does not appear to access private data, credentials, the network, or unrelated files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are very broad everyday expressions such as '今天吃什么' and '不知道吃啥', and the description says the skill should be used proactively. In an agent environment, this can cause the skill to activate in many normal conversations and automatically run code/persistent-history logic when the user did not clearly request this specific skill, increasing the chance of unintended execution and side effects.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal