Back to skill

Security audit

Umeå Lunch

Security checks across malware telemetry and agentic risk

Overview

This skill appears to only fetch public Umeå lunch menus from a disclosed website and format them for the user.

Install this if you want live Umeå lunch menu lookup. Be aware that using it contacts umealunchguide.se; the package is small and purpose-aligned, but the publisher could improve transparency by explicitly declaring the network domain in capability metadata.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill invokes a Python script that fetches live data from an external website, which implies network access, but the skill metadata does not declare that capability. Undeclared network behavior reduces transparency and can bypass least-privilege review, making it harder for users or the platform to assess what external communication the skill performs.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The description includes broad activation terms like lunch, restaurants, or food in Umeå, which can cause the skill to trigger in more situations than necessary. Over-broad routing is primarily a safety and reliability issue: it may invoke networked code unexpectedly, expose user queries to external fetching logic, or overshadow more appropriate skills.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.