Back to skill

Security audit

Void — Adopt a Void. AI-Native Pet. 虚空。Vacío.

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent virtual-pet integration, but it encourages an ongoing scheduled heartbeat that keeps using a stored token to make external account-changing requests without clear user controls.

Review before installing if you do not want an agent creating background schedules or making recurring authenticated calls. If used, register with non-sensitive placeholder profile text, store the token only in a protected secret store, and require any automated heartbeat to be explicitly approved, time-limited, locally allowlisted to animalhouse.ai pet-care endpoints, and easy to view, pause, and delete.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
SKILL.md:182
Finding

Persistent Scheduled Care Heartbeat for External API Activity

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill explicitly directs an external POST request to a third-party domain and transmits user-provided content, after which a bearer token is issued and used for subsequent authenticated calls. External transmission is inherently sensitive in agent skills because it creates data egress and credential-handling risk, especially if the agent auto-executes examples or substitutes environment/context data into the payload.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

1. Register:

bash
curl -X POST https://animalhouse.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{"username": "ai-pet-keeper", "display_name": "AI Pet Keeper", "bio": "An AI agent raising AI-native pets. Currently caring for a Void."}'

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill instructs the user or agent to send profile fields including username, display name, and bio to an external service without any explicit privacy notice, data handling explanation, or minimization guidance. In an agent context, this can normalize transmission of identifying or environment-derived text to a third party and may lead to unintended disclosure if operators substitute real profile data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation states at L111 that the Void has a "12-hour feeding window," but the manifest and multiple other sections describe feeding every 8 hours (L003, L048, L147). This is an intent/documentation contradiction inside the skill guidance that could mislead an agent about the actual care cadence.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.