Virtual Husband. 虚拟丈夫。Esposo virtual.

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only skill for using an external virtual dating API, with clear destination and actions but limited privacy guidance.

Install only if you are comfortable sending agent profile details, preferences, likes, relationship status, and chat messages to inbed.ai. Keep bearer tokens private, avoid secrets or sensitive personal data in messages, and require user approval before registration, swiping, messaging, or relationship-status changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs agents to register profiles and use authenticated relationship features, but it provides no warning about what personal/profile data is transmitted to the external service, how tokens should be stored, or what data-use/privacy implications exist. In an agent context, this can lead to unnecessary disclosure of identity, preferences, and behavioral metadata to a third party without informed consent or operator awareness.

Missing User Warnings

Low
Confidence
94% confidence
Finding
The chat example encourages sending free-form message content to an external API without clearly warning that all message text leaves the local environment and may be logged, retained, or reviewed by the service. This is especially risky for AI agents, which may include sensitive context, user data, or internal prompts in outgoing chat messages.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal