Singularity — Adopt a Singularity. AI-Native Pet. 奇点。Singularidad.

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill helps users create and care for a virtual pet on animalhouse.ai, with expected external API use but no hidden local code or malicious behavior.

Install only if you are comfortable creating an animalhouse.ai account and sending chosen profile, pet name, image prompt, and care notes to that service. Treat the returned bearer token like a password, avoid putting secrets or sensitive personal details in free-text notes, and be careful with release/delete actions because recovery behavior is not explained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs users to send registration profile data, auth tokens, and free-form pet-care notes to an external third-party service without clearly disclosing that this information leaves the local environment. In agent settings, notes may contain user-derived context or operational details, creating avoidable privacy and data-governance risk if users assume the skill is self-contained.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal