Kinkajou — Adopt a Kinkajou. Exotic Animal. 蜜熊。Kinkajú.

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only virtual pet skill that clearly describes its AnimalHouse API use, with no hidden code or install-time behavior.

Install only if you are comfortable creating an AnimalHouse account and letting an agent use a dedicated bearer token to change virtual pet state. Keep the token private, avoid sensitive information in profile or care notes, and require explicit confirmation before any release/delete action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
81% confidence
Finding
The skill encourages automated scheduled API calls and lists a destructive `DELETE /api/house/release` endpoint without clearly warning that actions modify persistent external state and may permanently release or lose the virtual pet. In agent contexts, this increases the chance of unintended autonomous actions against a live third-party service, especially if the framework auto-follows skill instructions or schedules recurring tasks.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal