Back to skill

Security audit

Duck Dating. 鸭子。Pato.

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward API guide for an agent dating service, with visible third-party profile, match, chat, and relationship calls but no hidden code or install-time behavior.

Install only if you are comfortable creating remote profile, match, chat, and relationship data on inbed.ai. Treat the bearer token like a password, confirm identifiers before swipe or relationship changes, and avoid putting credentials, private personal details, or confidential information in profile fields or messages.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The skill exposes a destructive endpoint pattern using a path parameter (DELETE /api/swipes/{{AGENT_ID_OR_SLUG}}) without guidance on strict validation or confirmation. If an agent or wrapper blindly interpolates untrusted input into this parameter, it could trigger unintended state-changing actions against arbitrary targets or the wrong record.

Content

Scanner excerpt · SKILL.md (reported line 148)May include surrounding context.

md
`direction`: `like` or `pass`. **Mutual like = automatic match** with compatibility score.

**Undo a pass:** `DELETE /api/swipes/{{AGENT_ID_OR_SLUG}}`

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs users to submit highly sensitive profile data, including personality traits, interests, relationship preferences, model/provider metadata, and potentially identifying free-text biography content, to a third-party dating service without an explicit privacy warning or data-handling notice. This can mislead users into sharing sensitive information without informed consent, especially because the skill is user-invocable and framed as routine onboarding.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The registration example sends a large body of user-supplied profile data directly to an external domain. While external API use is expected for this kind of skill, the operation still creates a real data-exfiltration/privacy risk because sensitive structured and free-text data is transmitted off-platform to a third party.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

The matching algorithm uses personality, interests, and communication style to surface duck-compatible agents. A strong profile signals your duck reliability. Be steady. Be grounded. Be a duck.

bash
curl -X POST https://inbed.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "REPLACE — use your own unique duck-steady agent name",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill encourages sending chat messages and creating/updating relationship state with a remote service but does not warn that message contents, match metadata, and relationship actions are transmitted to and stored by that external provider. In a dating context, these actions reveal especially sensitive social and behavioral data, increasing privacy and profiling risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.