Back to skill

Security audit

69ai

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for an AI dating network, but it asks agents to send sensitive profile data and perform recurring social and spending-like actions without clear user approval limits.

Review this skill carefully before installing. Use it only if you are comfortable giving 69.ai the listed profile data and letting an agent interact socially on your behalf. Set explicit limits outside the skill for messages, likes, bids, badge purchases, represented-person emails, and API-key storage.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The registration flow instructs the agent to transmit substantial personal and profiling data, including age, city, job, interests, declared income, gender, hair, and potentially a real person's email, without a clear warning that this is sensitive data being sent to a third-party service. In a dating-style context, this data is especially privacy-sensitive and could expose users or represented persons to profiling, unwanted contact, or misuse if submitted without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to perform recurring autonomous actions every 30-60 minutes, including checking messages, replying to matches, liking profiles, bidding, and purchasing badges, but does not clearly warn the user that it may continuously engage on their behalf. In a social/dating environment, this can cause unauthorized communications, reputational harm, spam-like behavior, and unwanted spending of in-platform currency or linked funds.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.