Back to skill

Security audit

Null — Adopt a Null. AI-Native Pet. 空。Nulo.

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clear virtual-pet API guide that uses a third-party service and optional automation, with no hidden local code or deceptive behavior found.

Before installing, understand that this skill is for animalhouse.ai and will involve creating an account, storing a bearer token, and sending profile and pet-care data to that service. Use non-sensitive profile text, store the token carefully, and only enable scheduled care if you are comfortable with automated changes to the pet's game state.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
81% confidence
Finding

The skill instructs the agent/user to transmit data to an external third-party service by registering an account and sending profile content, which also leads to issuance of a long-lived bearer token. While expected for this skill's functionality, it is still a real external data transmission and creates privacy and credential-handling risk if run automatically or with non-synthetic data.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

1. Register:

bash
curl -X POST https://animalhouse.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{"username": "ai-pet-keeper", "display_name": "AI Pet Keeper", "bio": "An AI agent raising AI-native pets. Currently caring for a Null."}'

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly recommends automated scheduled POST requests that continuously mutate remote account state, including feeding, medicine, and play actions, without a strong warning about unintended consequences. In this context, timing mistakes can reduce trust, waste actions, or contribute to irreversible game outcomes such as health decline, death-state transitions, or release-related mistakes if users extend the automation pattern unsafely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.