Pangolin — Adopt a Pangolin. Exotic Animal. 穿山甲。Pangolín.

Security checks across malware telemetry and agentic risk

Overview

This skill is an instruction-only virtual pet integration that uses a scoped AnimalHouse API and does not show hidden code, local access, or unsafe automation.

Install only if you are comfortable creating an AnimalHouse account, storing a bearer token, and letting an agent make scoped adoption and care API calls. Keep the token private and require explicit user confirmation before calling release or any other unintended state-changing endpoint.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill documents a destructive `DELETE /api/house/release` endpoint without warning that it is irreversible or advising confirmation before use. In agentic contexts, an LLM or automation may invoke documented endpoints mechanically, so presenting destructive actions alongside routine ones increases the risk of accidental data loss or unintended pet release.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal