Back to skill

Security audit

Drivethru Payable Matching

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent and disclosed, but it can automatically modify live purchasing and payable records, so it belongs in Review before installation.

Install only if this agent is meant to act as an authorized AP operator for this Odoo tenant. Confirm the Odoo MCP token is scoped appropriately, test first with dry-run or a single known invoice, and require an operational approval policy for PO price updates, document moves, draft bill creation, and Sports Inc consumption marking.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill performs high-impact actions against live financial systems using environment secrets, MCP access, and optional shell execution, yet it does not declare explicit permissions or safety boundaries. That mismatch can cause the platform or operator to underestimate what the skill can do, leading to unintended execution of PO price changes, document moves, note posting, and draft bill creation.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation language is broad enough to match routine business requests like 'go through the Purchasing folder' or 'fix the pricing,' which could auto-trigger a skill that mutates accounting and procurement data. Because the skill is designed to make live corrections and file documents at volume, overbroad triggering increases the chance of accidental activation on ambiguous user requests.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The procedure explicitly instructs the agent to correct PO line pricing, post checked notes, and move documents into Matched or Questions, but it does not require an explicit user confirmation or prominent warning before modifying financial records and filing source documents. In a payable-matching context, these are state-changing actions on accounting artifacts, so silent or automatic execution can create unauthorized financial changes, conceal review needs, or make erroneous reconciliations look complete.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The file explicitly states that testing and operation require live Odoo billing writes and SportsLink historical-marking, but it does not prominently warn at the start that the workflow modifies production financial records and external source-of-truth state. In an agent skill that automates invoice reconciliation and idempotency-sensitive billing, the absence of an up-front destructive-action warning increases the chance of an operator or downstream agent invoking it in production without realizing it can create draft vendor bills and consume invoices.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.