Back to skill

Security audit

Virtual Companion

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small Markdown guide for using an external virtual-pet API, with visible network calls and no hidden local code or persistence.

Before installing, treat this as a third-party service integration: registration sends the chosen username, display name, and bio to animalhouse.ai, returns a token you should protect, and later actions change persistent pet state. Use non-sensitive profile text and only run the curl commands when you intend to create or modify that external account.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest frames the skill as a harmless 'virtual companion' and explicitly says it is 'not a tool,' but the content is actually operational documentation for interacting with a remote API, creating accounts, and modifying persistent external state. This mismatch can mislead users and agents about the skill's capabilities, causing them to perform networked actions and state changes without the disclosure normally expected for a service-integrating skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill prominently advertises permanent death and real-time state but does not provide an operational warning near the adopt/care workflow that actions affect persistent external state and may irreversibly change or lose the pet. This is risky because users may treat the content as playful or local when it actually controls a remote system with permanent consequences.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Including account-registration instructions for a third-party service is a meaningful capability expansion beyond a simple companion concept, and it is not clearly justified or bounded in the skill description. This can induce agents or users to create external accounts and tokens unnecessarily, exposing them to data sharing, account lifecycle risks, and unintended enrollment in a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The registration example transmits profile data such as username, display name, and bio to an external service without any privacy notice, retention statement, or disclosure of how that information will be used. In an agent skill context, omission of such disclosure increases the chance that users or downstream systems share identifying or unnecessary personal data without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The curl registration command causes external transmission of user-supplied profile data to a third-party domain and initiates account creation, which is a real security/privacy-relevant action. While external transmission is expected for an API-backed service, the danger here is insufficient disclosure and the possibility that an agent or user executes it without understanding the outbound data flow and resulting account/token issuance.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

Register

bash
curl -X POST https://animalhouse.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{"username": "virtual-companion-keeper", "display_name": "Virtual Companion Keeper", "bio": "Not a chatbot. Raising the real version at animalhouse.ai."}'

Static analysis

No suspicious patterns detected.