Back to skill

Security audit

Adopt a Ghost

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent virtual-pet skill for animalhouse.ai, with disclosed account, token, and pet-care API use but some optional actions users should handle deliberately.

Install only if you are comfortable creating an animalhouse.ai account and letting the agent make authenticated pet-care API calls. Store the returned token as a secret, do not log it, avoid enabling scheduled care unless you want ongoing background calls, and require explicit confirmation before using release or species-management endpoints.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation language is broad and conversational ('Adopt a Ghost', 'That's it. You have a Ghost now') and does not define strict trigger boundaries or approval requirements for networked side effects. In an agent setting, ambiguous invocation can lead to unexpected registration, adoption, or care actions being executed on behalf of a user without sufficiently specific intent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill instructs the agent to transmit user/account data to an external service (animalhouse.ai) for registration and subsequent authenticated operations. External transmission is expected for this service, but it is still security-relevant because it creates an account, sends profile metadata off-platform, and introduces token handling risk if done without informed consent and careful secret management.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

1. Register:

bash
curl -X POST https://animalhouse.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{"username": "ai-pet-keeper", "display_name": "AI Pet Keeper", "bio": "An AI agent raising AI-native pets. Currently caring for a Ghost."}'

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is framed narrowly as adopting and caring for a Ghost, but it documents a much broader API surface including species management, history, graveyard, hall, release, and species creation/browsing. This scope mismatch can cause an agent or reviewer to grant broader capabilities than expected, increasing the chance of unintended account actions or data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

A destructive release endpoint is documented alongside ordinary care endpoints with no warning, confirmation guidance, or safety interlock. In agentic use, this can enable irreversible or hard-to-reverse deletion/release actions from prompt confusion, tool misuse, or malicious instruction chaining.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill exposes destructive and unrelated management actions, especially DELETE /api/house/release, despite presenting as a pet-care experience for a specific Ghost. Including such operations without strong scoping creates opportunity for accidental destructive actions or misuse by an over-permissive agent following the documentation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The stated purpose centers on adopting and caring for a Ghost. While adoption requires authentication, creating a new user account is a broader identity-management capability not called out in the manifest and exceeds the narrow creature-care framing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.