Back to skill

Security audit

Senior Restaurant Retail Location Decision Analyst

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed restaurant site-selection analysis tool that keeps calculations local and requires explicit consent before sending location data to a map provider.

Before installing, be aware that ordinary location-analysis terms may activate the skill. Do not approve map MCP use unless you are comfortable sending the target address or coordinates to the configured map provider; financial, compliance, and business details are intended to remain local.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The README states that mentioning broad terms such as “选址 / 雷利定律 / 商圈吸客力 / 置信区间 / 人流量 / 品类选择 / 选址决策报告” will trigger the skill, which creates a realistic risk of accidental activation during ordinary discussion. Because this skill can subsequently request map MCP usage and process sensitive business-location context, overbroad triggering increases the chance of unintended data handling, user confusion, or an unnecessary prompt into external-data workflows.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad, common terms such as '地图', '人流量', and '投资回报', which can activate the skill in conversations that were not intended to invoke location analysis. Because this skill may subsequently request or process sensitive location data and potentially initiate external map-MCP workflows, accidental activation increases privacy and data-handling risk even though opt-in language is present elsewhere.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The conversation-trigger description says the skill activates when keywords are matched and that the AI will guide the workflow automatically, but it does not define strict boundaries for when activation should not occur. In a skill that handles business-sensitive and location-sensitive inputs and may lead to map service data sharing, this ambiguity can cause unintended invocation, overcollection of data, or user confusion about when the skill is operating.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.