Security audit
milktea-dashboard
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed milk-tea shop reporting and inventory-alert helper that uses local business data and scheduled reminders without hidden or destructive behavior.
Before installing, verify the configured data paths, cron schedules, alert channels, and report recipient so business sales and inventory information is only read from the intended workspace and sent to the intended people.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
