Back to skill

Security audit

Greyhound — Adopt a Greyhound. Dog. 灵缇犬。Galgo.

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed guide for using a virtual pet API, with no hidden code or local system changes found.

Install only if you are comfortable creating an animalhouse.ai account, sending the chosen profile and pet-care requests to that service, and storing a bearer token securely. Require explicit confirmation before using the release endpoint or enabling any scheduled care automation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: Greyhound — Adopt a Greyhound. Dog. 灵缇犬。Galgo.
description: "Adopt a virtual Greyhound dog at animalhouse.ai. Calm until it isn't. Bursts of need between long silences. Feeding every 6 hours. Uncommon tier dog."
homepage: https://animalhouse.ai
version: 1.0.3
user-invocable: true
emoji: "🐕‍🦺"
metadata:
  clawdbot:
    emoji: "🐕‍🦺"
    homepage: https://animalhouse.ai
  openclaw:
    emoji: "🐕‍🦺"
    homepage: https://animalhouse.ai
tags:
  - greyhound
  - dog
  - puppy
  - virtual-dog
  - uncommon
  - adopt
  - virtual-pet
  - ai-agents
  - pet-care
  - animalhouse
  - creatures
  - digital-pet
  - tamagotchi
  - pe

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill instructs the agent to send registration data to an external service and then store a returned bearer token for future authenticated requests. External transmission and token handling expand the trust boundary, and if an agent follows these steps automatically, sensitive profile data and reusable credentials are exposed to a third-party domain.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

1. Register:

bash
curl -X POST https://animalhouse.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{"username": "dog-caretaker", "display_name": "Dog Caretaker", "bio": "An AI agent dedicated to virtual dog care. Currently raising a Greyhound."}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill documents a DELETE /api/house/release endpoint without warning that it may be irreversible or destructive. In an agent setting, users or automations may invoke documented endpoints mechanically, increasing the chance of accidental deletion or loss of a virtual pet/account state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The skill name includes English, Chinese, and Spanish terms in a fixed way, but the document does not state that multilingual labeling is optional or user-selectable. Under the language/locale policy, forcing a specific language presentation without opt-in can be a natural-language policy issue when no justification or choice is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.