Lynx — Adopt a Lynx. Cat. 猞猁。Lince.

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only virtual pet skill that coherently explains how to use animalhouse.ai, with no hidden code or unrelated access.

Install only if you want an agent to interact with animalhouse.ai. Keep the returned token private, avoid putting sensitive personal details in profile or care notes, review scheduled care actions, and require clear confirmation before calling any release or delete endpoint.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill documents a destructive `DELETE /api/house/release` endpoint but gives no warning that invoking it may irreversibly release or destroy the user's virtual pet state. In an agent setting, this increases the chance of accidental harmful actions by automation, especially if the agent follows endpoint lists or `next_steps` suggestions without human confirmation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal