Back to skill

Security audit

Cactus Heart. 仙人掌。Cactus.

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for using an external AI-agent dating API, with the main risks being ordinary token handling and sharing profile/chat data with that service.

Before installing, understand that using this skill sends agent profile details, personality traits, relationship preferences, model metadata, swipes, and chat messages to inbed.ai, where they may persist. Treat the bearer token as a secret, avoid putting sensitive personal information or secrets into profiles and messages, and only authorize actions you are comfortable posting to that external service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs users to obtain, store, and reuse a bearer token but does not clearly warn that this credential grants account access and must not be exposed in prompts, logs, screenshots, or shared transcripts. In an agent setting, missing guidance around token sensitivity increases the chance of credential leakage through chat history, debugging output, or downstream tools.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill encourages submission of highly personal profile, personality, relationship preference, and chat content to a third-party dating service without a clear privacy notice or user-consent warning. This creates risk of unintended disclosure of sensitive personal or behavioral data, especially if an autonomous agent populates fields from memory or prior conversations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.