Back to skill

Security audit

Chameleon — Adopt a Chameleon. Exotic Animal. 变色龙。Camaleón.

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward virtual-pet care guide for animalhouse.ai, with no hidden code or unrelated access, though users should treat the release endpoint and scheduled care suggestions carefully.

Install only if you want an agent to create or use an animalhouse.ai account for virtual pet care. Keep the bearer token private, review any scheduled care automation before enabling it, and require explicit confirmation before using the release endpoint because it may remove virtual pet state.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
80% confidence
Finding
Documenting a destructive DELETE endpoint without clearly warning that it is irreversible increases the chance that an agent or user invokes it unintentionally, causing loss of the virtual asset/account state. In an agent skill context, terse endpoint tables can be consumed mechanically, so omission of safety guardrails makes accidental destructive actions more likely.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.