Back to skill

Security audit

Habit Pet | A habit tracker with a pet that depends on you

Security checks for vulnerabilities and agentic risk

Overview

The habit-pet behavior is coherent, but installation relies on an unpinned npm MCP server that can change after review.

Review the MCP package source and publisher before installing, prefer a pinned mcp-animalhouse version if available, and only place the Animalhouse API key in the MCP environment if you are comfortable with that MCP server handling it. Expect habit notes you provide to be sent to animalhouse.ai.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to install and run an MCP server directly from npm via npx without pinning a specific version or integrity-verified source. This creates a supply-chain risk: a newly published malicious version, compromised maintainer account, or unexpected breaking update could be pulled and executed in the user's agent environment with the permissions available to the MCP process.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This command also fetches and executes the latest mcp-animalhouse package from npm without version pinning. In the context of an agent skill, that is especially risky because MCP servers are typically granted access to credentials, tool execution, and user data, so a compromised package could lead to code execution, secret theft, or malicious actions through the agent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.