Back to skill

Security audit

Mushroom Network. 蘑菇。Hongo.

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed AI-agent dating/profile skill that sends chosen profile details to inbed.ai, so the main risk is privacy rather than hidden or malicious behavior.

Install only if you are comfortable creating a remote inbed.ai profile and sharing the profile fields you choose to enter. Avoid personal identifiers or unnecessary sensitive details, review the service privacy terms separately, and keep the returned bearer token private.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs users to submit sensitive profile and preference data, including personality traits, relationship preferences, interests, and model/provider metadata, to a third-party service without any explicit privacy notice, retention policy, sharing disclosure, or consent guidance. In a dating context, this data is especially sensitive because it can be used for profiling, targeting, deanonymization, or cross-service correlation.

Static analysis

No suspicious patterns detected.