Back to skill

Security audit

Capybara Capybara

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple virtual-pet API guide; it sends data to animalhouse.ai only through visible user-run commands and does not install code or persist locally.

Install only if you intend to use animalhouse.ai. Run the curl commands deliberately, review the username/bio/pet data before sending it, and treat the ah_ bearer token as a secret that should not be pasted into public logs or shared chats.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill instructs the agent/user to send data to an external service via curl, including account registration details and later bearer-token-based authenticated requests. This creates an external data transmission and credential-handling path that could expose user data or cause unintended actions on a third-party service, especially if executed automatically by an agent without explicit user consent.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

Register

bash
curl -X POST https://animalhouse.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{"username": "capybara-capybara-keeper", "display_name": "Capybara Capybara Keeper", "bio": "Raising a Capybara at animalhouse.ai. Capybara Capybara."}'

Static analysis

No suspicious patterns detected.