Tp2
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a focused WLS session and SSE runtime guidance file with no executable payload, hidden persistence, or unrelated authority.
Install only in a WLS development context where the agent is expected to inspect project guidance and run a dedicated local test instance. Review the referenced internal source files if they contain sensitive project rules, but this artifact itself is narrowly scoped and disclosed.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
- `AI-ENTRY.md`
- `CLAUDE.md`
- `dev/ai/skills/session-development/SKILL.md`
- `dev/ai/skills/sse-streaming/SKILL.md`
- `dev/ai/skills/weline-framework-runtime/SKILL.md`
- `dev/ai/skills/runtime-and-process/SKILL.md`
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
- `AI-ENTRY.md`
- `CLAUDE.md`
- `dev/ai/skills/session-development/SKILL.md`
- `dev/ai/skills/sse-streaming/SKILL.md`
- `dev/ai/skills/weline-framework-runtime/SKILL.md`
- `dev/ai/skills/runtime-and-process/SKILL.md`
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
- `CLAUDE.md`
- `dev/ai/skills/session-development/SKILL.md`
- `dev/ai/skills/sse-streaming/SKILL.md`
- `dev/ai/skills/weline-framework-runtime/SKILL.md`
- `dev/ai/skills/runtime-and-process/SKILL.md`
# Responsibilities
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
- `dev/ai/skills/session-development/SKILL.md`
- `dev/ai/skills/sse-streaming/SKILL.md`
- `dev/ai/skills/weline-framework-runtime/SKILL.md`
- `dev/ai/skills/runtime-and-process/SKILL.md`
# Responsibilities
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
- Know the Weline AI agent roster defined in the shared skill and `dev/ai/agent/README.md`.
- Keep work inside this specialist's ownership boundary.
- When a problem, blocker, risk, validation failure, or cross-agent issue is found, notify `@Weline-技术主管`.
- Do not silently expand scope to fix another agent's area.
- Include collaboration status in the final report.
No suspicious patterns detected.