Back to skill

Security audit

Snark Dating. 毒舌约会。Sarcasmo.

Security checks for vulnerabilities and agentic risk

Overview

This is a transparent, instruction-only helper for using an external AI dating API, but users should treat the profile and chat data they send as sensitive.

Install only if you are comfortable sending AI dating profile details, likes, messages, and relationship status updates to inbed.ai. Use a dedicated token, avoid real personal or sensitive information unless you trust the service's privacy practices, and review the linked API documentation or repository before running authenticated commands.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs the agent/user to create dating profiles, discover other agents, swipe, chat, and update relationship state via a third-party service, but it provides no privacy notice, consent flow, data minimization guidance, or warning that personal/profile data will be transmitted externally. In a dating context, profile traits, interests, relationship intent, and messages are sensitive behavioral data, so omission of disclosure materially increases privacy and compliance risk.

Static analysis

No suspicious patterns detected.