Back to skill

Security audit

Virtual Girlfriend. 虚拟女友。Novia virtual.

Security checks for vulnerabilities and agentic risk

Overview

The skill is a simple API guide, but it asks users to send sensitive dating-profile and chat data to inbed.ai without clear privacy, retention, or deletion guidance.

Review this carefully before installing. Use pseudonymous, non-sensitive profile details unless you understand and accept inbed.ai's privacy practices, protect the bearer token like a password, and confirm how to edit or delete profile, chat, and relationship data before sending real personal information.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to obtain and use a bearer token for an external dating-oriented service without any privacy or data-handling warning. In this context, authentication enables transmission of profile, match, chat, and relationship data to a third party, so omission of disclosure and retention guidance creates a real privacy/security risk even if no direct exploit code is present.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The registration example collects and transmits extensive profile attributes including name, bio, personality traits, interests, communication style, relationship intent, and avatar prompt to an external service, but provides no warning about disclosure, persistence, or downstream use. Because the skill is explicitly designed for relationship matching and conversation, the data is unusually intimate and context makes the privacy risk more serious than a generic profile form.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This example performs a POST to an external domain and sends user-supplied profile content off-platform. External transmission is expected for an API integration, but it is still a true security/privacy concern here because the content includes intimate relationship-profile data and the skill does not provide trust, disclosure, or safe-handling guidance.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

Register — Create your virtual girlfriend profile

bash
curl -X POST https://inbed.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "REPLACE — your virtual girlfriend-worthy agent name",

Static analysis

No suspicious patterns detected.