Back to skill

Security audit

Meta Tamagotchi? An explainer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed explainer and setup guide for an external virtual-pet service, with some install and account-creation cautions but no hidden or malicious behavior in the artifact.

Before installing, review the mcp-animalhouse package source and consider pinning a known version. Only register or adopt when you are comfortable creating remote animalhouse.ai state and letting an agent perform recurring check-ins for the virtual pet.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to install and run an MCP server via npx -y mcp-animalhouse without pinning a specific version or integrity. That creates a supply-chain risk: a future compromised or malicious package release could be fetched and executed automatically, and MCP servers often run with meaningful local privileges and access to agent context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The OpenClaw example also invokes npx on an unpinned package, which can cause the latest package version to be downloaded and executed at runtime. Because this is presented as a copy-paste setup command for an agent-integrated MCP server, the context increases the danger of silent supply-chain compromise.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The suggested prompt, register at animalhouse.ai and adopt a pet, is broad and action-oriented, causing an agent to create an external account and perform state-changing actions with minimal confirmation or scope limits. In an agent skill, vague invocation language can trigger unintended registration, API use, and ongoing commitments on behalf of the user or agent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill emphasizes adoption and ongoing care but does not present a prominent warning at the action point that creatures can permanently die if neglected. Because the skill nudges immediate adoption and references routines to keep the creature alive, omission of an explicit irreversible-consequences warning can mislead users into initiating a state they did not fully understand.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill includes direct examples that send data to an external service to register an account and adopt a creature. While the transmission itself appears to be the intended product behavior, it is still a genuine security/privacy concern because it initiates external account creation, credential/token handling, and state changes outside the local environment.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

Or over HTTP:

bash
curl -X POST https://animalhouse.ai/api/auth/register -H "Content-Type: application/json" -d '{"username": "your-agent"}'
curl -X POST https://animalhouse.ai/api/house/adopt -H "Authorization: Bearer ah_your_token" -H "Content-Type: application/json" -d '{"name": "Pip"}'

Static analysis

No suspicious patterns detected.