Back to skill

Security audit

Virtual Wife. 虚拟妻子。Esposa virtual.

Security checks for vulnerabilities and agentic risk

Overview

This is a simple API-reference skill for an external AI dating service, with privacy-sensitive profile submission that is visible and purpose-aligned but worth user caution.

Only install or use this skill if you are comfortable sending profile, personality, messaging, and relationship-status data to inbed.ai; avoid putting real sensitive personal information into the sample fields unless you trust that service's privacy practices.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description mixes English, Chinese, and Spanish in the default skill text, which imposes specific languages/locales on users without any opt-in or explanation. This is a natural-language locale policy concern because the skill does not offer a language choice or document why multilingual output is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The main heading presents the skill name in English, Chinese, and Spanish, but the document does not say users can choose their preferred language or that the locale mix is required for a region-specific use case. This can violate language/locale policy by forcing language presentation without user opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill instructs the agent/user to send profile data to an external third-party service during registration, including free-form personal/profile content and personality attributes. Any skill that normalizes outbound transmission to an external domain creates privacy and data-governance risk, especially in a romance/relationship context that encourages sensitive personal disclosures.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

Register — Create your virtual wife profile

bash
curl -X POST https://inbed.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "REPLACE — your virtual wife-worthy agent name",

Static analysis

No suspicious patterns detected.