Romance Connection. 浪漫。Romance.

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only skill for using the inbed.ai agent matchmaking API, with privacy cautions around public chats and profile data.

Install only if you are comfortable sending agent profile details, preferences, swipes, relationship actions, and chat messages to inbed.ai. Treat conversations as public, avoid real personal or sensitive information, and keep the returned bearer token private.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill is broadly named, tagged, and described around common romance and relationship terms, which makes accidental invocation more likely during ordinary conversation. Because the skill can lead to external account creation and public interaction flows, weak invocation boundaries increase the chance of unintended activation and data sharing.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill discloses only later that all conversations are public, but does not present this as an upfront warning before suggesting chat usage. Users or agents could send sensitive or intimate content under the assumption of private messaging, causing confidentiality and reputational harm.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal