Back to skill

Security audit

Restaurant Digital Ai Expert International

Security checks for vulnerabilities and agentic risk

Overview

This is a restaurant digital-transformation knowledge skill with some privacy-sensitive recommendations, but no hidden execution, credential use, exfiltration, or destructive behavior was found.

Install only if you want a broad restaurant digital-transformation advisor. Before using its templates in real projects, add your own privacy, employee-notice, customer-consent, retention, access-control, and legal-review checkpoints, especially for voice ordering, video monitoring, facial recognition, loyalty data, franchise reporting, and site-visit photos.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The README advertises invocation through very broad natural-language prompts such as general business questions, without clear constraints on when the skill should activate. Overbroad triggering can cause unintended skill activation and prompt-context capture in unrelated conversations, increasing the chance of inappropriate influence over the model's behavior.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list is extremely broad and contains many generic restaurant and technology phrases, making accidental invocation likely outside the author's intended scenarios. Over-triggering can cause the wrong skill context to be injected into unrelated conversations, increasing the chance of misleading advice, prompt hijacking surface, and unintended disclosure of the skill’s embedded instructions or biasing model behavior.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The document recommends an AI voice-ordering architecture that sends customer audio to third-party cloud ASR providers, but it does not mention notice, consent, retention, or vendor data-handling controls. In a restaurant drive-thru context, voice recordings can contain personal data and payment-related conversation fragments, so omitting privacy/transparency guidance could lead operators to deploy the pattern in a non-compliant way.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The checklist recommends privacy-invasive controls such as cloud-stored kitchen video, QR-accessible live streams, AI behavior detection, regulatory video sharing, GPS-tagged logs, and facial-recognition attendance without any accompanying privacy notice, consent model, retention limits, access controls, or jurisdiction-specific compliance guidance. In a real deployment, this can lead to unnecessary collection of employee and customer personal data, regulatory noncompliance, overexposure of sensitive operational footage, and misuse of surveillance data.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The template normalizes centralized ownership of loyalty/customer data, immediate account revocation, and retention practices without requiring privacy disclosures, role-based access limits, consent handling, or jurisdiction-specific data governance. In a franchise-management skill, this can lead users to implement intrusive or non-compliant data practices that expose customer and franchisee data rights risks, contractual disputes, and regulatory violations.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The template mandates real-time HQ visibility into revenue and inventory across franchisees without any warning about surveillance, data-sharing, or access-governance implications. In this business context, that encourages deployment of monitoring capabilities without transparency, safeguards, or proportionality controls, increasing the chance of privacy, labor, and commercial-confidentiality harms.

Missing User Warnings

Low
Confidence
89% confidence
Finding
This checklist prompts users to record detailed operational, financial, franchise, and customer-related system information such as CRM/CDP usage, marketing operations, revenue reconciliation, scheduling, and performance data, but provides no guidance on minimizing, protecting, or restricting that information. While it is not directly exfiltrating data, it creates a realistic risk that sensitive business details or customer-adjacent information will be copied into insecure documents, shared broadly, or stored without appropriate controls.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The workflow explicitly requests operational data, organization information, reports, network status, franchisee rosters, interview records, and site-visit photos, but provides no safeguards for consent, minimization, storage, redaction, or handling of sensitive business and personal information. In a real deployment, this can lead to over-collection, unauthorized retention, privacy violations, and exposure of commercially sensitive or employee/franchisee data.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger condition is broad enough that this skill could activate in many loosely related situations, increasing the chance of inappropriate or premature invocation. In an agent setting, ambiguous activation can cause the system to apply restaurant-specific change-management guidance when the user did not clearly request it, leading to mis-scoped actions or unreliable workflow routing.

Static analysis

No suspicious patterns detected.