Friends
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill is classified as suspicious due to its direct instruction to interact with the user's file system by creating and managing files within `~/friends/` (as specified in `SKILL.md`). While this capability is plausible for a 'personal friendship system,' it represents a significant risk vector if the AI agent's environment is not perfectly sandboxed or if it could be tricked into directory traversal or arbitrary file writes via prompt injection. Additionally, the skill explicitly tracks sensitive personal data about friends, which, while necessary for its function, poses a privacy risk if not handled securely by the underlying platform.
