Back to skill

Security audit

Food Order

Security checks across malware telemetry and agentic risk

Overview

The skill is purpose-aligned for Foodora reordering and tracking, with clear confirmation safeguards before purchases.

Install only if you trust `ordercli` and are comfortable with it accessing your Foodora account or browser session. Use Foodora-specific requests, review any preview carefully, and only give explicit confirmation when you want an order placed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases include broad actions like 'order food' and 'reorder' without sufficient scope constraints, which can cause the skill to activate in ambiguous contexts. Because this skill can ultimately place commercial orders and modify a user's cart, overbroad triggering raises the risk of unintended invocation that could lead to accidental purchases or exposure of account/order data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.