Shiba Inu — Adopt a Shiba Inu. Dog. 柴犬。Shiba Inu.

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only virtual pet skill that tells an agent how to use animalhouse.ai APIs, with no hidden code or install-time behavior found.

Install only if you are comfortable letting an agent use an animalhouse.ai token to manage a virtual pet account. Keep the token private, approve any recurring care automation yourself, and do not call the release/delete endpoint unless you intentionally want to remove or abandon the pet.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill documents a DELETE /api/house/release endpoint but gives no warning that it may be irreversible or destructive. In an agent context, undocumented destructive actions can be invoked by automation or misinterpretation, leading to accidental loss of a user's virtual pet or account state.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal