Back to skill

Security audit

AI桌面宠物

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent static desktop-pet web skill, with some privacy and scoping notes but no evidence of hidden, destructive, persistent, or exfiltrating behavior.

Reasonable to install if you want a static browser-based pet. Be aware that the UI and emotion keywords are Chinese-focused, the docs should be clearer that inspected photo/text processing is local, and the browser will load Three.js from unpkg.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises photo upload for color extraction and emotion-text analysis, but provides no notice about what data is processed, whether processing is local or remote, whether content is stored, or what privacy expectations users should have. Even if the implementation is purely client-side, omission of privacy and handling details can mislead users into sharing sensitive personal data without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README presents Chinese emotion recognition as a built-in behavior without indicating language limitations, user choice, or explicit opt-in. This can cause inaccurate inference, exclusion of non-Chinese users, and unintended analysis of user emotional content without clear consent, though the security impact is lower than direct data exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises photo upload and emotion detection, both of which involve potentially sensitive personal data, but it does not clearly explain what data is processed, whether it leaves the device, how long it is retained, or what user consent is required. This creates privacy risk because users may provide face images or intimate emotional disclosures without understanding handling boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad enough to activate the skill not only on explicit requests to open the pet, but also whenever a user expresses distress or wants comfort. In an emotional-support context, this can cause unsolicited engagement, misfire on sensitive conversations, and increase the chance that privacy-sensitive emotion or personal context is processed without clear consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The feature list explicitly states '中文情绪识别,' indicating the skill recognizes emotional input in Chinese only. This is a language/locale constraint, but the document does not clearly present it as an opt-in choice or justify the restriction as a region-specific tool, which may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The page declares lang="zh-CN" and the visible interface text throughout the file is exclusively in Simplified Chinese. Under the policy rule, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.