Adopt A Chonk

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only virtual pet skill whose token-protected API calls match its stated animalhouse.ai pet-care purpose.

Install only if you are comfortable creating an animalhouse.ai account token and sending pet-care actions and notes to that service. Store the bearer token in a secret store, avoid placing private information in care notes, and enable scheduled check-ins only when you intend recurring external API calls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs users to obtain, store, and reuse a bearer token, but provides no guidance on secret handling, scope minimization, redaction, or avoiding accidental disclosure in logs and transcripts. In an agent setting, this increases the risk that the token is stored insecurely, echoed back to users, or sent to other tools, enabling account takeover of the pet-management account.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal