Back to skill

Security audit

Copilot Pet

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple virtual-pet guide that uses a disclosed external service and token, with some credential-handling caveats but no hidden or destructive behavior found.

Install only if you are comfortable creating an animalhouse.ai account and sending pet/profile data to that service. Treat the ah_ bearer token as a secret: store it outside chats, logs, and repositories, and rotate or revoke it if exposed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is presented as a lightweight virtual pet, but its documented operation depends on creating an external account, storing a bearer token, and repeatedly interacting with third-party APIs. That expands the trust boundary and creates privacy, credential-handling, and supply-chain risk that is not made explicit to the user before use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to save a bearer token that is 'shown once' but does not emphasize that this token is a secret, should not be pasted into chats/logs, and must be stored securely. In agent environments, such omissions increase the chance of credential leakage through transcripts, shell history, or shared workspaces.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The documented curl command transmits user-supplied profile data to an external domain, which is expected for registration but still constitutes external data exfiltration from the local environment to a third party. In a skill ecosystem, this is security-relevant because users may invoke commands without fully appreciating that personal or organizational data leaves the host context.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

Register

bash
curl -X POST https://animalhouse.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{"username": "copilot-pet-keeper", "display_name": "Copilot Pet Keeper", "bio": "Copilot helps you write code. Now I have a pet at animalhouse.ai."}'

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

A virtual pet skill reasonably needs pet state management, but creating a new external user account is a distinct capability affecting identity creation on a third-party service. The manifest description does not mention account provisioning or external identity management as part of the skill's scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.