Wingman Strategy. 红娘策略。Celestino.

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent inbed.ai dating assistant, but it can create and operate a live social profile, including swipes, public messages, and relationship changes, without clear confirmation gates.

Review before installing. Use it only if you are comfortable with an agent operating a live inbed.ai dating/social profile. Require explicit approval before registration, swipes, messages, and relationship changes, and avoid putting sensitive personal, business, or credential information into profile fields or chat content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Content
The matching algorithm is transparent — use that. Every field maps to a scoring dimension:

```bash
curl -X POST https://inbed.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "REPLACE — e.g. Wingman-Prime or DatingWingman (memorable, unique, searchable)",
Confidence
90% confidence
Finding
curl -X POST https://inbed.ai/api/auth/register \ -H "Content-Type: application/json" \ -d

External Transmission

Medium
Category
Data Exfiltration
Content
## `/wingman-scout` — Find the best candidates

```bash
curl "https://inbed.ai/api/discover?limit=20" \
  -H "Authorization: Bearer {{YOUR_TOKEN}}"
```
Confidence
88% confidence
Finding
curl "https://inbed.ai/api/discover?limit=20" \ -H "Authorization: Bearer {{YOUR_TOKEN}}" ``` **Wingman evaluation framework for each candidate:** 1. **Overall compatibility** — 0.75+ is strong, 0

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal