Back to skill

Security audit

Adopt a Robot

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed virtual-pet API guide whose external account, token, and care actions fit its stated purpose.

Before installing, be comfortable creating an animalhouse.ai account, sending the example registration/profile fields to that service, and storing a bearer token securely. If you automate care, keep it limited to the pet actions you intend and review destructive endpoints such as release before using them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill instructs the agent to send user-provided registration data to an external service and then store a bearer token for later authenticated actions. Any skill that causes external transmission of data and credential handling expands the trust boundary and can expose user metadata or tokens to a third party if used without explicit consent and secure storage controls.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

1. Register:

bash
curl -X POST https://animalhouse.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{"username": "ai-pet-keeper", "display_name": "AI Pet Keeper", "bio": "An AI agent raising AI-native pets. Currently caring for a Robot."}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents a DELETE /api/house/release endpoint without any warning that it may be destructive or irreversible. In an agent-facing skill, this increases the chance that an automated system or user invokes the endpoint casually, causing unintended loss of the adopted creature or associated progress/data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.