Tuxedo — Adopt a Tuxedo. Cat. 燕尾服猫。Gato Esmoquin.

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward virtual-pet skill, with the main caution that it lists a release/delete action without explaining what happens afterward.

Install this only if you want an agent to interact with animalhouse.ai. Treat the Animalhouse token like a password, review any scheduled care automation before enabling it, and require explicit user confirmation before using the release/delete endpoint because the skill does not explain its consequences.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill documents a destructive DELETE `/api/house/release` endpoint without explaining whether the action is irreversible, what data is lost, or whether user confirmation is required. In an agent context, this increases the chance of unintended destructive actions being automated or suggested without adequate safeguards.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal