Back to skill

Security audit

fridge-keeper

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent fridge-management skill, but it needs review because it stores database credentials plainly and contains unsafe database update code.

Install only if you are comfortable with a skill keeping fridge inventory on disk or in your chosen database. Avoid putting real database passwords in the config file unless you can restrict file permissions and use a dedicated low-privilege database account. Treat the database mode as needing hardening before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/storage.py:150
Finding

SQL Injection Through Unvalidated Update Column Names

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/storage.py:18
Finding

Database Credentials Stored in Plaintext Without Enforced File Permissions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/storage.py:110
Finding

Unpinned Database Driver Installation Guidance

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill describes local file reads/writes and config persistence but does not declare any explicit tool scope or permissions boundary. This can lead to overbroad file access at runtime, making unintended reads/writes or privilege expansion harder to audit and constrain.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill supports remote database storage and collects connection details, including credentials, but provides no warning about privacy, network transmission, or credential-handling risks. In context, this increases the chance that users send sensitive inventory and secrets to remote systems without understanding exposure, encryption, or retention implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill persists configuration and food inventory to local files but does not clearly warn users that their data will be stored on disk. Users may unknowingly leave sensitive household or routine information in plaintext local storage, increasing privacy and forensic exposure on shared or compromised systems.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The query trigger phrases such as “有什么/查看冰箱/当前食物” are broad enough to overlap with normal conversation, which can cause accidental invocation of the skill. In a stateful skill that reads and writes persistent data, misfires may expose private inventory data or trigger unintended actions in the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Using the generic trigger word “建议” for recipe recommendations is overly ambiguous and can collide with ordinary assistant interactions. That raises the chance of accidental activation, causing unnecessary access to stored fridge contents and potentially disclosing user data in unrelated conversations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code deletes stored items from the local data file and immediately persists the change, but there is no confirmation prompt, warning message, or explanatory comment indicating that the action is destructive. For a code file, irreversible data deletion should include some visible disclosure unless the destructive behavior is clearly surfaced elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The MySQL delete_item method permanently removes rows from the fridge_items table and commits the transaction immediately, but the code provides no user disclosure, confirmation, or warning about the destructive effect. This is a safety-relevant irreversible operation under the code-file criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The PostgreSQL delete_item method executes a DELETE statement and commits it without any visible disclosure that the operation is destructive. Because the removal is irreversible at the storage layer, the file should provide some warning or require callers to confirm intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This method permanently deletes a document from the MongoDB collection with no confirmation, prompt, or warning text in the code. Under the missing-user-warnings rule for code files, destructive storage operations should surface their impact to users or be explicitly documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

描述与触发短语完全以中文给出,呈现出该技能默认面向中文交互的约束,但文档没有说明这是可选语言设置,也没有提供用户选择其他语言的方式。按规则,强制特定语言而无用户选择可构成语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is entirely written in Chinese and presents the skill behavior and data guidance only in that language, with no indication that users may choose another language or locale. This can violate a language/locale policy when a skill effectively mandates a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file's natural-language interface elements are written in Chinese, and no mechanism is indicated for user language choice or locale opt-in. Under the policy rule, forcing a specific language without user choice can be a locale-policy issue unless the regional constraint is clearly documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.