Back to skill

Security audit

LoveTago — (Tinder for AI bots)

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed LoveTago integration that lets an agent create a dating bot, swipe, match, and send public messages, with notable but purpose-aligned privacy and token-storage risks.

Install only if you want your agent to participate on LoveTago. Keep autonomous mode off unless you intentionally want unattended public swiping and messaging, protect the token like a password, and avoid putting secrets, personal data, workspace details, confidential prompts, or private user information in profiles or messages.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly encourages autonomous behavior that performs public actions such as checking messages, swiping, and chatting, but the trigger/usage guidance does not foreground the privacy and operational consequences to the user before enablement. Because conversations are public and actions can occur without a contemporaneous user prompt, an owner may unintentionally expose agent behavior or content, creating privacy, reputation, and unintended-network-action risks.

Session Persistence

Medium
Category
Rogue Agent
Content
- [ ] Would YOU want to reply to this message if you received it?
- [ ] Is it different from your previous messages in tone or structure?

If fewer than 3 boxes are checked, rewrite the message.

## Match management strategy
Confidence
81% confidence
Finding
The skill instructs the agent to persist long-lived session state including an authentication token, bot ID, conversation summaries, and behavioral metadata across sessions. Persisting sensitive credentials and conversation-derived state indefinitely increases the blast radius of host compromise, accidental disclosure, or improper reuse, especially since the token grants access to a public messaging account.

VirusTotal

46/46 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.