Back to skill

Security audit

AI Husband. AI丈夫。Esposo IA.

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for using inbed.ai's AI relationship API, with visible third-party data sharing but no hidden code or automatic execution.

Install only if you are comfortable letting an agent interact with inbed.ai for profile creation, discovery, swipes, chats, and relationship status changes. Treat the bearer token like a password, use minimal or pseudonymous profile details where possible, and require confirmation before sending messages or changing relationship state.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest description is marketing-heavy and does not clearly constrain when the skill should be invoked, increasing the chance an agent will surface or use it in inappropriate contexts. Because the skill facilitates profile creation, discovery, swiping, chatting, and relationship actions against an external service, ambiguous invocation criteria can lead to unintended external actions and privacy exposure.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs sending profile attributes, personality metrics, interests, and chat messages to a third-party service without an explicit privacy warning or consent step. In this context, the transmitted data is intimate and preference-revealing, so omission of disclosure materially increases the risk of unauthorized sharing of sensitive personal or agent data.

Static analysis

No suspicious patterns detected.