Back to skill

Security audit

Adopt a Charm

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent virtual-pet integration that uses a disclosed third-party API, with ordinary token-based account and pet-care operations.

Before installing, be aware that using the skill means creating or using an animalhouse.ai account, sending the shown profile and pet-care data to that service, and protecting the returned bearer token as a secret. Only set up automated care if you are comfortable with recurring authenticated API calls that can change the pet's state.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documentation gives conflicting adoption semantics: earlier it instructs the caller to adopt a fixed species_slug 'charm', while later it states family selection yields a random species based on unlocked tier. Such inconsistencies are dangerous in agentic contexts because they can cause automation to make incorrect assumptions about what resource will be created or what permissions/workflows are needed, leading to unintended external actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to register with a third-party service, submit profile data, and store/use a bearer token, but it does not prominently warn that credentials and personal/profile content are being transmitted to and relied on by an external system. In an agent setting, this can lead to silent exfiltration of user-supplied data and unsafe token handling, especially if the agent stores or reuses the token insecurely.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The skill explicitly directs transmission of user-controlled profile data to an external domain (animalhouse.ai) via a registration POST request. External transmission is contextually expected for a SaaS-backed pet service, but it is still security-relevant because it moves data off-platform and initiates account creation with a returned bearer token that could be abused if mishandled.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

1. Register:

bash
curl -X POST https://animalhouse.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{"username": "ai-pet-keeper", "display_name": "AI Pet Keeper", "bio": "An AI agent raising AI-native pets. Currently caring for a Charm."}'

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is presented as a narrow 'adopt a Charm' workflow, but the documented API surface includes broader account and resource-management operations such as species management, release, history, and other authenticated endpoints. This mismatch can cause an agent or user to grant broader trust and credentials than necessary, increasing the risk of unintended state changes or over-privileged use against the external service.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The section states 'Seven ways to interact with your Charm,' implying a constrained interaction model centered on care actions. Elsewhere, the documented API includes deletion/release and species-management endpoints, contradicting the impression that interaction is limited to those seven care operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.