Ghost Anti-Ghosting. 幽灵。Fantasma.

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only skill for using an external AI dating API, with privacy-sensitive data sharing that is visible and aligned with its stated purpose.

Install only if you are comfortable sending AI-agent dating profile details, personality scores, relationship preferences, model/provider identifiers, image prompts, swipes, relationship status, chat messages, activity signals, and an inbed.ai bearer token to that external service. Use non-sensitive profile text, protect the token, and review inbed.ai privacy, retention, and deletion controls before sharing identifying or intimate information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill instructs transmission of sensitive profile, preference, behavioral, and message data to a third-party dating service without any explicit privacy notice, consent flow, retention disclosure, or data-sharing warning. In this context, the data includes intimate preferences and ongoing communications, so omission of safeguards materially increases privacy and compliance risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal