Back to skill

Security audit

Openai Pet

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only virtual pet skill whose animalhouse.ai API calls match its stated purpose.

Before installing, treat the animalhouse.ai token like a password: store it securely, avoid sharing or committing it, and rotate it if exposed. Also avoid putting sensitive personal or business information in usernames, bios, pet names, notes, or image prompts because those are sent to animalhouse.ai.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation instructs users to obtain and use a bearer token and notes it is shown only once, but does not explicitly warn that the token is a sensitive secret that must not be logged, shared, or committed. In agent/tooling environments, such omissions can lead to accidental secret exposure through chat history, terminal logs, screenshots, or repositories.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.