Back to skill

Security audit

Coding Buddy

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward virtual pet API guide, with expected use of an Animalhouse account token and no evidence of hidden or destructive behavior.

Install only if you are comfortable creating an animalhouse.ai account and letting the agent use its bearer token to manage the virtual pet. Store the token in a secret manager or environment variable, avoid committing or logging it, and rotate or revoke it if exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
81% confidence
Finding
The skill instructs users to save a bearer token that is 'shown once' but does not explicitly warn that it is a secret, should not be committed, logged, shared, or pasted back into chat/tools. In an agent-skill context, that omission increases the chance of credential exposure and unauthorized use of the user's animalhouse.ai account.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.