Back to skill

Security audit

Restaurant Digital Ai Expert 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This is a large restaurant digital transformation guidance skill with some overbroad and privacy-sensitive advice, but it does not execute code, hide behavior, or request unusual system access.

Install only if you want a Chinese-language restaurant digitalization consulting aid. Treat its templates as drafts, not legal or privacy-complete policies: have counsel or a privacy/security lead review any franchise data sharing, customer traceability, camera livestream, GPS, or facial recognition plan before implementation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (16)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger section invites activation through very general natural-language requests such as common business questions, without clear boundaries for when the skill should or should not engage. In an agent environment, overly broad activation can cause unintentional routing to this skill, leading to inappropriate context capture, response shaping, or interference with other safer or more relevant skills.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill advertises extremely broad trigger coverage across 120+ Chinese and English terms, which increases the chance of accidental or inappropriate invocation outside the user's intended context. In an agent ecosystem, overbroad invocation can cause prompt hijacking of unrelated tasks, unnecessary exposure of internal instructions, and misrouting of user requests to a domain-specific skill that may override safer defaults.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill uses absolute language such as claiming it can answer 'any time, any restaurant format, any digital problem' without constraints. This can cause the orchestrator or downstream model to over-trust the skill, apply it to out-of-scope scenarios, and suppress uncertainty handling, which is risky when the content includes technical, legal, compliance, and investment guidance.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill metadata hard-codes 'zh-CN' as the language/locale without indicating fallback to user preference or explicit opt-in. This can lead to unsafe misunderstandings in multilingual environments, especially for operational, financial, or compliance guidance where incorrect language assumptions may distort user intent or output meaning.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This section explicitly mandates centralized collection and headquarters control of franchisee revenue, inventory, and member data, but provides no safeguards around privacy, lawful basis, access control, minimization, or franchisee/customer consent. In a business operations skill, this is dangerous because it normalizes broad surveillance and data appropriation as a default control mechanism, which can lead to privacy violations, contractual abuse, and unauthorized cross-store data use if implemented as written.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The exit section directs immediate account revocation, continued retention of member data by headquarters, and limited return of operational data, without addressing legal rights, continuity of operations, portability, or secure offboarding procedures. That creates a real risk of coercive lock-in, improper retention, denial of access to business-critical records, and privacy noncompliance during franchise termination.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The checklist recommends continuous kitchen video monitoring, cloud retention, consumer livestream access, and AI behavior recognition, but omits any privacy, consent, retention, access control, or legal-compliance safeguards. In a real deployment, this can lead to over-collection of employee and customer-adjacent personal data, unauthorized disclosure, and regulatory noncompliance, especially where biometric or surveillance data is involved.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The traceability section links ingredient batches to sold dishes and specific customers via POS/member systems, which creates identifiable purchase histories tied to food consumption. Without warnings about minimization, retention, access controls, and incident-response handling, this exposes sensitive personal data and increases the harm from misuse, insider access, or breach.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The digital records section proposes GPS-tagged records, facial-recognition attendance, cloud storage, mobile signatures, and photo-based evidence without any safeguards for sensitive data processing. These features can collect biometric, location, and identity data far beyond what is strictly necessary for food safety operations, creating privacy, security, and labor-compliance risks if implemented as written.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger conditions are extremely broad: any first contact related to restaurant digitalization can invoke the workflow. In an agent setting, this can cause the skill to activate on routine conversation outside a clearly scoped task, leading to unintended data collection, persuasive sales behavior, or workflow takeover when the user only asked a general question.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrase "帮我们写个方案/Proposal" is broad and overlaps with common conversational requests, so the workflow may activate in contexts where the user did not intend to invoke the proposal-generation skill. In an agent system, overly permissive triggers can cause incorrect routing, unintended disclosure of internal workflow behavior, or execution of proposal-generation logic on unrelated inputs.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases include very broad natural-language inputs like “帮写SOW” and “合同怎么谈”, which can overlap with ordinary conversation and cause the skill to activate unintentionally. In an agent environment, over-broad activation can route unrelated user content into contract-generation guidance, increasing the chance of context confusion, unintended actions, or disclosure of sensitive business information into the wrong workflow.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrase “帮我们全面看看数字化水平” is broad, natural-language wording that could easily appear in ordinary conversation and unintentionally activate this workflow. In an agent skill system, overly generic triggers increase the chance of accidental invocation, context bleed, or routing a user into a sensitive business-diagnostics flow without explicit intent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger condition is very broad: once a 'digital strategy is determined,' the workflow may activate without clear scoping, readiness checks, or role/organization prerequisites. In an agentic system, overly broad triggering can cause this skill to run in unintended contexts and produce authoritative organizational recommendations that are misaligned, but the content itself does not contain directly dangerous instructions.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger condition '数字化项目批准,进入正式实施阶段' is broad and lacks explicit trigger phrases, scope guards, or exclusions, so the skill may activate in loosely related implementation discussions rather than only when the user is clearly requesting PMO/implementation methodology. In an agent setting, over-broad activation can cause unintended context injection, workflow confusion, or execution of irrelevant guidance, though this file does not contain direct destructive actions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The quick-lookup table maps very broad, everyday user utterances directly to specific workflows, which can cause the agent to over-trigger structured consulting flows from minimal conversational cues. In a skill designed as a large end-to-end expert workbench, this increases the chance of scope misclassification, unwanted behavior routing, and reduced user control, especially when phrases like 'I want to learn about digitalization' or 'we want to do AI' are common and ambiguous.

Static analysis

No suspicious patterns detected.