Basenji — Adopt a Basenji. Dog. 巴仙吉犬。Basenji.

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed virtual-pet care guide that uses the AnimalHouse API, with one caution around an under-explained release/delete endpoint.

Install only if you are comfortable giving the agent an AnimalHouse token and letting it make care-related API calls. Treat the release/delete endpoint as destructive: require a direct confirmation before any call to /api/house/release, and review any scheduled care automation so it only performs the actions you intend.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
79% confidence
Finding
The skill documents a DELETE `/api/house/release` endpoint but provides no warning that invoking it may permanently delete or release the virtual pet. In agentic contexts, undocumented destructive actions can be triggered by automation or user misunderstanding, causing irreversible state loss even if the impact is limited to the pet/account data.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal