Greyhound — Adopt a Greyhound. Dog. 灵缇犬。Galgo.

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only virtual pet skill whose API usage matches its stated animalhouse.ai care workflow, with minor cautions around token handling and the release endpoint.

Safe to install if you intend to use animalhouse.ai. Keep the issued API token private, review any scheduled-care automation before enabling it, and only use the release endpoint after an explicit user decision because it changes pet state.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill documents a destructive `DELETE /api/house/release` endpoint without any warning, confirmation guidance, or explanation of irreversibility. In an agentic setting, this increases the chance that an LLM or automation invokes the endpoint accidentally, causing unintended permanent state loss for the user's virtual pet/account resources.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal