Tp2
High
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
- Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Security audit
Security checks for vulnerabilities and agentic risk
This is a simple frontend-development guidance skill with broad but disclosed scope and no hidden code, credential access, persistence, or execution behavior.
Install only if you want a broadly scoped Chinese-language frontend helper that defaults to React, shadcn/ui, Tailwind CSS, TypeScript, and Next.js when you do not specify a stack. Review task requests carefully because the triggers are general frontend phrases, but the artifact itself contains no executable payload or hidden privileged behavior.
No suspicious patterns detected.