Tamagotchi Pet

Security checks across malware telemetry and agentic risk

Overview

This looks like a disclosed virtual-pet integration, but users should understand it sends account and pet data to animalhouse.ai and may create public or persistent pet records.

Install only if you want to use animalhouse.ai through your agent. Do not paste bearer tokens into shared chats, avoid sensitive personal information in usernames, bios, pet names, image prompts, or care notes, and confirm you are comfortable with any public or permanent virtual-pet records before registering or adopting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs users to register, adopt, and care for a pet through an external service but does not clearly warn that user-supplied content and bearer tokens are sent to a third-party domain. This can lead users or calling agents to disclose data to an external service without informed consent and increases the risk of accidental token exposure or privacy violations.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The description markets the service while mentioning permanent death and a public graveyard, but it does not present these outcomes as a clear pre-use warning before encouraging registration and adoption. Users may unintentionally create public, persistent records or engage with irreversible actions without understanding the consequences.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal