Back to skill

Security audit

qsr-audit-readiness-countdown

Security checks across malware telemetry and agentic risk

Overview

This is a conversation-only restaurant audit preparation coach with some disclosed record-keeping and a non-operational promotional link.

Before installing, be aware that the skill may record audit findings, corrective actions, scores, and names or roles of responsible staff. Use roles instead of full names when possible, and do not enter confidential corporate documents unless your organization allows it. The Observa beta link appears promotional and is not required to use the skill.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Low
Confidence
87% confidence
Finding
The skill description and notes frame this as a conversational audit-preparation coach with no integrations required. However, the publisher note inserts an external call-to-action URL for an unrelated Observa beta program, which goes beyond the described operational behavior of the skill itself.

Context-Inappropriate Capability

Low
Confidence
90% confidence
Finding
A QSR audit-readiness coaching skill does not need to advertise or route users to a private beta for governance tooling. This capability is not part of helping operators prepare for EcoSure, health department, or brand audits and is contextually out of scope.

Missing User Warnings

Low
Confidence
85% confidence
Finding
The markdown explicitly defines a memory format that includes respondent name/role and audit findings, which can constitute personnel or sensitive operational data. The skill description does not provide any warning about storing this information, retention, or avoiding unnecessary personal details.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.