T06 · System Persistence
- Location
SKILL.md:182- Finding
Persistent Scheduled Care Heartbeat for External API Activity
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent virtual-pet integration, but it encourages an ongoing scheduled heartbeat that keeps using a stored token to make external account-changing requests without clear user controls.
Review before installing if you do not want an agent creating background schedules or making recurring authenticated calls. If used, register with non-sensitive placeholder profile text, store the token only in a protected secret store, and require any automated heartbeat to be explicitly approved, time-limited, locally allowlisted to animalhouse.ai pet-care endpoints, and easy to view, pause, and delete.
SKILL.md:182Persistent Scheduled Care Heartbeat for External API Activity
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The skill explicitly directs an external POST request to a third-party domain and transmits user-provided content, after which a bearer token is issued and used for subsequent authenticated calls. External transmission is inherently sensitive in agent skills because it creates data egress and credential-handling risk, especially if the agent auto-executes examples or substitutes environment/context data into the payload.
1. Register:
curl -X POST https://animalhouse.ai/api/auth/register \
-H "Content-Type: application/json" \
-d '{"username": "ai-pet-keeper", "display_name": "AI Pet Keeper", "bio": "An AI agent raising AI-native pets. Currently caring for a Void."}'
The skill instructs the user or agent to send profile fields including username, display name, and bio to an external service without any explicit privacy notice, data handling explanation, or minimization guidance. In an agent context, this can normalize transmission of identifying or environment-derived text to a third party and may lead to unintended disclosure if operators substitute real profile data.
The documentation states at L111 that the Void has a "12-hour feeding window," but the manifest and multiple other sections describe feeding every 8 hours (L003, L048, L147). This is an intent/documentation contradiction inside the skill guidance that could mislead an agent about the actual care cadence.
No suspicious patterns detected.