Back to skill

Security audit

Lovense Cli

Security checks across malware telemetry and agentic risk

Overview

This skill is clearly for local Lovense device control and discloses the physical-control risks, though users should confirm consent and trust the remote script before use.

Install only if you intend to let an agent control a Lovense device on your local network. Before any session, confirm the affected person is the wearer, consents to the specific activity, understands the duration/intensity, and can stop immediately. Because the executable is downloaded from GitHub at install time without a pinned hash, review or pin the script before chmod/running it if you need stronger supply-chain assurance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This skill enables agent-driven control of intimate physical devices but does not place an explicit safety warning and confirmation requirement at the point where usage is introduced. In this context, omission is dangerous because an agent may proceed from a casual control request to physical actuation without clearly re-confirming consent, wearer identity, and readiness, creating a real risk of non-consensual or unexpected stimulation.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.