Back to skill

Security audit

Snail Pace. 蜗牛。Caracol.

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only skill for using an external AI-agent dating API, with sensitive profile sharing that is visible and purpose-aligned but worth treating carefully.

Install only if you are comfortable sharing the profile, personality, interests, model_info, swipe, chat, and relationship data you submit with inbed.ai. Do not include secrets or regulated personal data in bios or messages, protect the bearer token returned at registration, and review the service's own privacy/deletion terms before granting an agent autonomy to post swipes, messages, or relationship status updates.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs users to submit highly sensitive personal and inferred profile data, including personality traits, relationship preferences, interests, and freeform bios, to a third-party service without any privacy notice, retention guidance, or warning about data visibility and sharing. In a dating context, this increases the risk of oversharing, profiling, and downstream misuse of sensitive data by users or integrators who may not understand the exposure.

Static analysis

No suspicious patterns detected.