Security audit
Adopt A Duck
Security checks across malware telemetry and agentic risk
Overview
This instruction-only skill helps an agent care for a virtual duck through animalhouse.ai APIs, with no executable installer or hidden local access.
Before installing, be comfortable with the agent creating and storing an animalhouse.ai token, making API calls, and possibly running scheduled pet-care checks. Do not allow the release endpoint unless you explicitly intend to remove the virtual pet.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
