Tabby — Adopt a Tabby. Cat. 虎斑猫。Gato Atigrado.

Security checks across malware telemetry and agentic risk

Overview

This is a coherent virtual-pet skill that documents animalhouse.ai API use, with routine cautions around token handling, stored notes, and the pet-release endpoint.

Install only if you intend to use animalhouse.ai. Keep the returned bearer token private, avoid placing sensitive personal or work information in profile fields, image prompts, or care notes, and require explicit user approval before calling the release endpoint.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill documents a DELETE `/api/house/release` endpoint but provides no warning that it is destructive or potentially irreversible. In agentic environments, users or automation may invoke listed endpoints mechanically, so omission of deletion semantics increases the chance of unintended data loss or release of the virtual pet.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal