Beagle — Adopt a Beagle. Dog. 比格犬。Perro Beagle.

Security checks across malware telemetry and agentic risk

Overview

This is a virtual pet care skill that uses AnimalHouse API calls as advertised, with some cautions around tokens, scheduled care, and a release endpoint.

Install this if you want an agent to manage a virtual pet on animalhouse.ai. Keep the bearer token private, avoid putting sensitive information in pet names or notes, approve any recurring care schedule deliberately, and require explicit confirmation before using DELETE /api/house/release.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
76% confidence
Finding
The skill advertises a destructive DELETE release endpoint without any warning about irreversibility, confirmation requirements, or recovery expectations. In agentic contexts, undocumented destructive operations increase the chance of accidental invocation, leading to unintended deletion or loss of a user's virtual pet state/data.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal