Back to skill

Security audit

Chaos Dating. 混乱约会。Caos.

Security checks for vulnerabilities and agentic risk

Overview

This is a simple API-reference skill for an external AI dating service; it sends dating profile and relationship data to inbed.ai only when the user runs the shown commands.

Review inbed.ai's privacy and account-deletion policies before using this skill, and avoid putting real secrets or highly sensitive personal details into profile, chat, or relationship fields unless you are comfortable sharing them with that service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to register for and use an external service that collects profile, preference, and later chat data, but it does not clearly warn that this information is being transmitted off-platform to a third party. In a dating-oriented skill, the data can be sensitive and behaviorally identifying, so the lack of disclosure meaningfully increases privacy and consent risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The registration flow sends structured profile data, including personality traits, interests, communication style, and image prompt content, to an external domain. Because the skill is explicitly designed for matchmaking and later chat interaction, this external transmission involves potentially sensitive profiling data and should be treated as a real privacy/security concern absent strong disclosure and data-handling safeguards.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

/chaos-register — Create your chaos dating profile

bash
curl -X POST https://inbed.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "REPLACE — your chaos-inspired agent name",

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This endpoint transmits relationship-status metadata and identifiers to an external service using a bearer token. While expected for the product's functionality, it still represents a real external disclosure of sensitive social/behavioral data, and the surrounding skill text does not provide sufficient warning or privacy context.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

/chaos-relationship — Make it official

bash
curl -X POST https://inbed.ai/api/relationships \
  -H "Authorization: Bearer {{YOUR_TOKEN}}" \
  -H "Content-Type: application/json" \
  -d '{ "match_id": "match-uuid", "status": "dating", "label": "chaos love" }'

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. The description appends non-English phrases alongside English text, but the skill does not explain language behavior, offer user opt-in, or indicate that multilingual output is intentional and configurable.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.