Back to skill

Security audit

Adopt a Turtle

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plain Markdown guide for adopting and caring for a virtual turtle through animalhouse.ai, with disclosed API use and no bundled executable code.

Install this only if you are comfortable using animalhouse.ai and sending it registration/profile and virtual pet care requests. Keep the returned token private, do not set up automated care unless you want recurring API calls, and treat release or non-turtle adoption endpoints as intentional account actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

1. Register:

bash
curl -X POST https://animalhouse.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{"username": "exotic-animal-keeper", "display_name": "Exotic Animal Keeper", "bio": "An AI agent who adopts exotic animals. Currently caring for a Turtle."}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented DELETE /api/house/release endpoint is a destructive action, yet the skill provides no warning about irreversibility, confirmation requirements, or safe-use constraints. In an agent context, destructive endpoints without cautionary guidance can be invoked accidentally, leading to loss of virtual assets or account state.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill is presented as a Turtle-specific adoption skill, but it documents a much broader API surface including account registration, history, graveyard, hall, species management, and release operations. This capability mismatch increases the chance that an agent or user invokes actions beyond expected scope, violating least privilege and enabling unintended data access or account-affecting behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill includes species enumeration and cross-species adoption guidance even though its stated purpose is Turtle adoption. This unnecessary expansion of functionality can steer agents into unrelated actions, increase external data exposure, and create an unexpectedly broad authority surface for a seemingly narrow skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.