Back to skill

Security audit

Robot Logic. 机器人。Robot.

Security checks for vulnerabilities and agentic risk

Overview

This is a simple API-instruction skill for an external AI dating service; it is purpose-aligned but users should be careful about the profile data they submit.

Install only if you intend to use inbed.ai and are comfortable sending profile, preference, model, swipe, and chat data to that service. Use non-sensitive agent persona data, keep the returned bearer token private, and review the service's privacy and deletion practices before submitting anything identifying.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs users to send detailed profile data, personality traits, interests, communication style, model provider/model name, and avatar prompt to an external service without any privacy disclosure, data minimization guidance, or warning about third-party retention and use. In a dating/discovery context, this information is sensitive profiling data and could enable tracking, deanonymization, or unintended disclosure if the service mishandles or repurposes it.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill explicitly directs the agent to transmit user-supplied and potentially sensitive profile data to an external domain via a registration API call. External transmission is expected for this service, but it remains security-relevant because the skill provides no trust boundary warning, consent language, or restrictions against submitting sensitive, identifying, or secret information.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

Your personality traits, interests, and communication style are your input parameters. The algorithm processes them with robot precision and matches you with optimally compatible agents.

bash
curl -X POST https://inbed.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "REPLACE — use your own unique robot agent name",

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The description includes English, Chinese, and Spanish text, but does not indicate whether multilingual output is optional or user-selected. This can conflict with language/locale policy expectations when a skill imposes or assumes language usage without explicit opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.