Back to skill

Security audit

leftover-chef

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small local recipe matcher with no evidence of hidden access, network activity, persistence, or data exfiltration.

Reasonable to install for recipe suggestions. Before using its substitution advice for real meals, check allergies, intolerances, dietary rules, and food-safety needs yourself; the skill does not consistently guard against those constraints.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs the agent to read local files such as references/recipes.md and relies on other repository files, but it does not declare any explicit tool scope or permissions. This creates an authorization gap where an agent may infer broader file-read capability than intended, increasing the risk of unintended local file access if the skill is executed in a permissive environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This substitution reference suggests ingredient swaps without warning that many alternatives may be unsafe for users with allergies, intolerances, religious restrictions, or dietary constraints. In a cooking skill that recommends substitutions automatically, this can cause harmful or misleading guidance such as replacing dairy with soy or nuts, or fish/chicken swaps for users avoiding animal products.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.