Back to skill

Security audit

Virtual Pet MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a transparent virtual-pet MCP integration, with some install and API-key handling hygiene risks users should understand.

Before installing, consider pinning mcp-animalhouse and Smithery to reviewed versions instead of using unpinned npx commands. Store the API key only in a trusted secret/config location, avoid sharing transcripts that contain it, and review destructive actions such as releasing a pet before allowing them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The install command invokes npx to fetch and execute mcp-animalhouse without pinning an exact version. That allows future upstream package changes, compromise of the npm package, or dependency confusion-like scenarios to alter what users run at install time, which is especially risky for an MCP server that will be granted tool execution and access to local environment variables.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This command runs mcp-animalhouse via npx without a pinned version, so users will execute whatever version npm resolves at that time. In the context of an MCP server, an unexpected upstream change or compromised release could result in arbitrary code execution on the host and access to sensitive local context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The JSON config example also references mcp-animalhouse without pinning a version, so clients that launch it through npx may silently pick up newer or malicious releases. Because this is a persistent MCP configuration, the risk is recurring rather than one-time: every new environment or reinstall may execute unreviewed code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The Smithery bootstrap command executes smithery through npx without a pinned version, creating the same unpinned remote code execution exposure during installation. Even though this is an installer/helper package rather than the MCP server itself, compromising it could still lead to installation of malicious components or arbitrary code execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation states that register_agent returns an API key shown once and suggests storing it in ANIMALHOUSE_API_KEY in MCP config, but it does not clearly warn that MCP configs may be plaintext and that displaying the key in session output can expose it to logs, transcripts, screenshots, or other agents. In an MCP context, credential mishandling is more dangerous because the host may persist tool outputs and config files broadly across local tooling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.