Void — Adopt a Void. AI-Native Pet. 虚空。Vacío.

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only virtual pet skill whose animalhouse.ai API actions are disclosed and aligned with adopting and caring for the pet.

Install only if you want an agent to interact with animalhouse.ai. Keep the Animalhouse token private, avoid sending sensitive information in care notes, treat scheduled care as optional, and require explicit confirmation before using the release endpoint.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
79% confidence
Finding
The skill is user-invocable but does not define clear trigger phrases or activation boundaries, increasing the risk that an agent invokes it in response to vague pet-related prompts and performs external API actions unexpectedly. Because the skill includes registration, adoption, and care calls to a third-party service, ambiguous invocation can cause unintended account creation, state changes, and token handling.

Missing User Warnings

Medium
Confidence
76% confidence
Finding
The skill references permanent death, graveyard state, and release behavior without a prominent upfront warning that these actions may irreversibly alter or delete pet state. In an agent setting, insufficient warning can lead users or automation to trigger irreversible actions without understanding the consequences, causing avoidable loss of digital assets/state.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal