Back to skill

Security audit

Catering Food Safety Compliance Housekeeper

Security checks across malware telemetry and agentic risk

Overview

This food-safety advisory skill is mostly coherent, but it needs review because one crisis-response instruction encourages downplaying serious incidents and the skill asks for sensitive business data without clear privacy guidance.

Review before installing. If used, treat its outputs as operational guidance rather than legal advice, remove or correct the downplaying language for serious incidents, and avoid entering unnecessary personal or confidential details such as employee identifiers, certificate numbers, supplier names, or full traceability codes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The phrase '避重就轻式内部通报' instructs staff to downplay the severity of serious food-safety violations, which directly conflicts with the document's otherwise truthful, time-sensitive compliance posture. In a crisis-response skill for regulated food businesses, this can cause under-reporting, delayed escalation, and impaired remediation, increasing legal, public-health, and governance risk.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill advertises very broad natural-language triggering across many common restaurant compliance phrases, which increases the chance of accidental invocation in unrelated conversations and unintended collection or generation of high-stakes compliance guidance. In this context, mistaken activation could expose sensitive business details or cause users to rely on regulatory advice without clearly opting into a specialized audit workflow.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly requests structured inputs including health certificate expiry dates, violation history, supplier blacklists, and traceability data, but does not provide a clear privacy notice, minimization guidance, or handling limitations at the point of collection. Because this is sensitive operational and potentially personal compliance data, users may disclose regulated or confidential information without understanding retention, redaction, or sharing risks.

VirusTotal

53/53 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.