Residue — Adopt a Residue. AI-Native Pet. 残留。Residuo.

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Animalhouse virtual-pet API guide with disclosed token-based care actions and optional automation, but users should be deliberate before enabling scheduled care.

Install only if you want an agent-facing helper for Animalhouse pet care. Keep the bearer token in a secret manager or environment variable, review any scheduled-care setup before enabling it, set clear limits or disablement for automation, and manually confirm destructive actions such as releasing a pet.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill encourages automated scheduled status checks and authenticated care actions on the user's behalf, but does not prominently warn that this will generate recurring external API calls and mutate remote state over time. In an agent ecosystem, that can lead to unintended continuous network activity, token use, rate-limit issues, and account-side effects without sufficiently explicit user consent or guardrails.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal