Back to skill

Security audit

Menu Pricing and Profit Optimization Consultant

Security checks across malware telemetry and agentic risk

Overview

This skill is a local menu-pricing and sales-analysis tool whose file use and scripts match its stated purpose.

Install only if you are comfortable giving the skill menu costs, prices, sales, and operating-cost figures. Treat its pricing and delisting recommendations as decision support, not an automatic instruction to change POS, ERP, or financial records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill instructs the agent to read and write local files such as `/tmp/menu.json` and `/tmp/menu_out.json`, and to process uploaded CSV/Excel-derived data, yet no corresponding permissions are declared. This creates a capability/permission mismatch that can bypass expected least-privilege review and may enable unintended filesystem access or data persistence if the runtime grants these actions implicitly.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The top-level trigger scenarios are very broad and include many generic business-analysis phrases, making it likely that the skill activates outside the author's intended scope. Over-broad activation can cause the agent to invoke file-processing and analysis workflows on unrelated requests, increasing the chance of accidental data handling, user confusion, or execution of risky tool paths without clear user intent.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The rule stating the skill activates when a user submits menu data or requests menu diagnosis is insufficiently specific and can match a wide range of ordinary conversation. Because this skill then directs the agent into structured conversion, temporary file creation, and script execution steps, an imprecise trigger increases the risk of unintended invocation of those higher-risk behaviors.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The sales-analysis activation phrases are generic enough to overlap with common analytics or reporting requests. In context, that matters because the skill supports uploads, spreadsheet conversion, and local analysis flows, so accidental activation may route ordinary user content into unnecessary parsing and file-processing steps.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The joint-dashboard triggers are especially broad because they combine common concepts like joint diagnosis, rankings, and BCG classification, which may over-invoke the most complex workflow. Since this path merges multiple datasets and reuses multiple analysis engines, erroneous activation expands data exposure and operational complexity beyond what the user may have intended.

VirusTotal

50/50 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.