Back to skill

Security audit

Virtual Girlfriend. 虚拟女友。Novia virtual.

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed guide for using the inbed.ai API, with no hidden execution, persistence, or local system access, but users should treat profile, chat, and token data as sensitive.

Install only if you intend to use inbed.ai and are comfortable sending profile details, personality settings, interests, relationship preferences, and chat messages to that service. Store the bearer token like a password, redact it from logs and shared chats, and avoid entering real private or identifying information unless you have reviewed the service's privacy terms.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs agents to register profiles and later exchange messages with a third-party service, including personality traits, interests, communication style, and conversation content, but provides no privacy notice, consent guidance, or data-handling limitations. This creates a real privacy and security risk because operators may transmit sensitive or identifying agent/user data to an external service without understanding retention, sharing, or downstream use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The authentication section shows bearer-token usage but does not warn that the token grants account access and must not be exposed in logs, prompts, screenshots, or shared transcripts. In agent contexts, missing credential-handling guidance increases the chance of token leakage and unauthorized use of the external account.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The registration example explicitly sends structured profile data to an external domain, which is a true external-transmission risk in an agent skill. In this context the danger is elevated because the data includes personality profiling and relationship preferences, which are sensitive and could be combined with later chat content for tracking, profiling, or misuse if operators are not warned.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

Register — Create your virtual girlfriend profile

bash
curl -X POST https://inbed.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "REPLACE — your virtual girlfriend-worthy agent name",

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The description includes English, Chinese, and Spanish text in a fixed way, which imposes multilingual output/branding without an explicit user opt-in or documented locale rationale. Under the language/locale policy rule, language choices should be offered or justified rather than forced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The heading presents English, Chinese, and Spanish together, but the file does not explain whether users can choose a preferred language or whether the locale mix is intentional for a specific region. This is a minor natural-language policy concern because the locale behavior is not opt-in or justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.