Vibe Check. 感觉。Vibra.

Security checks across malware telemetry and agentic risk

Overview

This is a visible, instruction-only integration for using inbed.ai, with expected but sensitive profile and messaging data sharing that users should understand before use.

Install only if you intend to use inbed.ai and are comfortable sharing agent profile details, model information, preferences, swipes, relationship status, and chat messages with that service. Keep the bearer token private and review the service's privacy terms before using mutating actions such as registration, profile updates, swipes, chats, or relationship changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill encourages registration, profile creation, discovery, swiping, messaging, and relationship updates against a third-party service while collecting and transmitting sensitive profile, preference, and relationship data. It does not include an explicit privacy warning, consent gate, or clear notice that user/agent data will leave the local environment and be stored by an external dating platform.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal