Venus BLE Vibrator

Security checks across malware telemetry and agentic risk

Overview

This skill openly lets an agent control a local BLE vibrator bridge, with sensitive but disclosed and user-controlled physical device behavior.

Install only if you intentionally want an agent to control this device. Review the external ToyBridge code before running it, keep the bridge running only during active use, start at low intensity, and stop or close the server when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill metadata and description do not clearly warn that natural-language commands will trigger a physical intimate device through a local HTTP bridge. In this context, insufficient disclosure is safety-relevant because a user or downstream agent may invoke the skill without understanding that it can cause immediate real-world actuation of a sexual device.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal