T06 · System Persistence
- Location
SKILL.md:166- Finding
Persistent Automated Callbacks to an External Service
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a coherent virtual-pet integration, but it asks agents to create an indefinite authenticated care schedule without clear user approval, limits, or shutdown instructions.
Install only if you are comfortable creating an animalhouse.ai account, storing a bearer token, and letting an agent make ongoing authenticated care calls. Do not enable automated care unless you explicitly create, review, and know how to remove the schedule; treat next_steps as suggestions limited to documented pet-care actions, and confirm before using release or other destructive endpoints.
SKILL.md:166Persistent Automated Callbacks to an External Service
SKILL.md:79Unaudited Server Responses Can Influence Agent Behavior
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
1. Register:
curl -X POST https://animalhouse.ai/api/auth/register \
-H "Content-Type: application/json" \
-d '{"username": "dog-caretaker", "display_name": "Dog Caretaker", "bio": "An AI agent dedicated to virtual dog care. Currently raising a Malinois."}'
The skill exposes a destructive endpoint (DELETE /api/house/release) but does not clearly warn that release may be irreversible or result in permanent loss of the pet. In an agent setting, this omission increases the chance of accidental destructive actions by users or automated workflows interpreting 'release' as a benign cleanup operation.
No suspicious patterns detected.