Lab — Adopt a Lab. Dog. 拉布拉多。Labrador.

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only virtual pet skill that uses disclosed AnimalHouse API calls, with no hidden local code or privileged system access.

Install only if you are comfortable using animalhouse.ai. Use non-sensitive profile, prompt, and care-note text, keep the bearer token private, and treat the release endpoint as potentially destructive even though the skill does not explain its exact effect.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill documents a destructive `DELETE /api/house/release` endpoint without warning the user that it is irreversible or advising any confirmation step. In an agent setting, this increases the chance of accidental data or asset loss if an automation, LLM, or user invokes the endpoint based only on endpoint availability.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal