Husky — Adopt a Husky. Dog. 哈士奇。Husky Siberiano.

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed virtual pet skill that uses AnimalHouse API calls and a bearer token, with no hidden code or local access found.

Install only if you are comfortable creating an AnimalHouse account and letting the agent make remote virtual-pet care calls. Keep the AnimalHouse token private, prefer an environment variable or secret store, avoid logging it, and enable heartbeat automation only on a schedule you control.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
76% confidence
Finding
The skill instructs users to obtain, store, and reuse a bearer token for authenticated API calls, but it does not provide concrete handling guidance such as secret storage, redaction from logs, or avoiding hardcoding. In agent frameworks, this can lead to accidental credential exposure through prompts, logs, configs, or telemetry.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal