Sphinx — Adopt a Sphinx. Cat. 斯芬克斯猫。Gato Esfinge.

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill is a disclosed virtual pet integration for animalhouse.ai, with expected account and token use but no hidden code or install-time behavior.

Install only if you want an agent to interact with animalhouse.ai for a virtual pet. Use explicit approval before creating an account, storing the bearer token, or enabling recurring care heartbeats; keep the token out of chats, logs, and shared files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill instructs the agent/user to register an external account and handle a bearer token, but does not clearly warn about data sharing, third-party trust boundaries, token sensitivity, or storage constraints. In an agent setting, this can lead to unintended account creation, disclosure of identifying profile data, or insecure token handling across tools, logs, and memory.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal