Back to skill

Security audit

expiry-tracker

Security checks for vulnerabilities and agentic risk

Overview

This is a local food-expiry tracking CLI with bounded, disclosed persistence and no evidence of hidden, network, credential, or destructive behavior beyond its own inventory file.

Before installing, understand that this stores grocery inventory and notes in ~/.expiry_tracker.json and that remove uses fuzzy matching, so review matches carefully. Treat expiry dates as planning estimates only; check food condition and storage history before eating or discarding anything.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code generally aligns with the broad goal of tracking food expiry dates and offering 'use today' suggestions to reduce waste. It supports manual item entry, expiry estimation, urgent-item listing, and recipe/use hints. However, key declared capabilities are missing: there is no receipt scanning or OCR/parsing from receipts, and there is no scheduler, notification, or trigger-based daily alert system. Instead, the tool is a CLI that only shows alerts when explicitly invoked. The code also adds an undeclared but related reporting capability for consumed/wasted items. Because important user-facing features in the description are absent, the description does not accurately represent the actual behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill describes commands that read and write a persistent JSON database in the user's home directory, but it does not declare any tool scope or permissions boundary. That creates an authorization and transparency gap: a host or reviewer cannot easily determine what file access the skill expects, and overly broad file capabilities may be granted by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document encourages using food that is near or at its expiry window but does not prominently instruct users to check for spoilage, storage conditions, package integrity, or food-specific safety rules before consuming it. In a food-expiry tracking skill, users may over-trust the guidance and eat unsafe dairy, meat, fish, or produce, increasing the risk of foodborne illness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script stores food inventory and notes in a persistent file at ~/.expiry_tracker.json, which is user data written outside the current working directory. Although the write path is visible in code, there is no user-facing warning in the usage text or help output that personal inventory data and optional notes will be persisted on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

cmd_remove deletes matching items from the database and records them as consumed or wasted, then saves the modified state. Because matching is fuzzy and the operation changes persisted user data, a mistaken invocation could remove multiple entries without any confirmation or prior warning.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.