Axolotl — Adopt an Axolotl. Exotic Animal. 六角恐龙。Ajolote.

Security checks across malware telemetry and agentic risk

Overview

This is a coherent virtual-pet skill for animalhouse.ai, with a caution that one documented endpoint may release the pet and should be used only intentionally.

Install only if you are comfortable creating an animalhouse.ai account and storing the returned bearer token securely. Treat adoption, care automation, and especially DELETE /api/house/release as real remote state changes, and confirm before releasing a pet.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill advertises a destructive `DELETE /api/house/release` endpoint without explaining whether the action is irreversible, what data or assets are lost, or whether confirmation is required. In agent contexts, this increases the chance of accidental destructive actions triggered by automation, vague user prompts, or tool misuse, leading to unintended deletion or release of the user's virtual asset.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal