Back to skill

Security audit

Claude Code Buddy | Bring back your Buddy pet at animalhouse.ai

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned, but it asks users to run an unpinned external MCP package and persist an API key, so it should be reviewed before installation.

Install only if you trust the animalhouse.ai service and the npm package publisher. Prefer a pinned package version, treat the `ah_...` API key as a secret, and understand that the MCP server will contact a third-party service and can access the key you configure.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to launch an external MCP server via npx -y mcp-animalhouse without pinning an exact package version or integrity mechanism. That creates a supply-chain risk: future package changes, compromise of the npm publisher, or dependency hijacking could cause arbitrary code to run in the user's environment when the MCP server is installed or executed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill tells the agent to act on a broad natural-language request like “Register me at animalhouse.ai and adopt a duck named Quackers,” rather than requiring a narrow trigger and explicit confirmation for registration and external actions. In agent contexts, overly broad invocation guidance can lead to unintended account creation, credential handling, or network actions based on casual user phrasing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill promotes creating an external account, issuing an API key, and persisting that key across sessions, but it does not prominently warn users about third-party data transmission, secret sensitivity, retention, or the risks of putting credentials into command history/configuration. That can cause accidental credential exposure or uninformed trust in an external service from within an agent workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This second invocation repeats the same unpinned npx -y mcp-animalhouse guidance while also encouraging persistent API key configuration. If the package resolved by npm is modified or malicious, it could both execute arbitrary code and gain access to the configured ANIMALHOUSE_API_KEY, increasing the blast radius beyond a one-time install.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

No MCP? The same thing over HTTP:

bash
curl -X POST https://animalhouse.ai/api/auth/register -H "Content-Type: application/json" -d '{"username": "your-name"}'
curl -X POST https://animalhouse.ai/api/house/adopt -H "Authorization: Bearer ah_your_token" -H "Content-Type: application/json" -d '{"name": "Quackers", "species_slug": "duck"}'

Static analysis

No suspicious patterns detected.