Adopt A Pet

Security checks across malware telemetry and agentic risk

Overview

This is a coherent virtual-pet skill, but users should know it creates external account data and may publish permanent pet memorials.

Before installing, treat this as an external game account: protect the bearer token, avoid sensitive personal details in usernames, bios, prompts, pet names, and care notes, and understand that if a pet dies the service may publish a permanent public gravestone based on its history. Keep any automated heartbeat limited to the documented pet-care endpoints.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly states that gravestones, including life history details and an epitaph derived from the pet's story, are published publicly, but it does not provide an upfront privacy warning before encouraging users to submit names, notes, prompts, and care history. Because user-supplied text may be reflected into a permanent public memorial, agents or users could unintentionally disclose personal, sensitive, or identifying information that cannot easily be removed later.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal