Tp2
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent virtual-pet integration that uses a disclosed third-party API, with ordinary token-based account and pet-care operations.
Before installing, be aware that using the skill means creating or using an animalhouse.ai account, sending the shown profile and pet-care data to that service, and protecting the returned bearer token as a secret. Only set up automated care if you are comfortable with recurring authenticated API calls that can change the pet's state.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The documentation gives conflicting adoption semantics: earlier it instructs the caller to adopt a fixed species_slug 'charm', while later it states family selection yields a random species based on unlocked tier. Such inconsistencies are dangerous in agentic contexts because they can cause automation to make incorrect assumptions about what resource will be created or what permissions/workflows are needed, leading to unintended external actions.
The skill instructs users to register with a third-party service, submit profile data, and store/use a bearer token, but it does not prominently warn that credentials and personal/profile content are being transmitted to and relied on by an external system. In an agent setting, this can lead to silent exfiltration of user-supplied data and unsafe token handling, especially if the agent stores or reuses the token insecurely.
The skill explicitly directs transmission of user-controlled profile data to an external domain (animalhouse.ai) via a registration POST request. External transmission is contextually expected for a SaaS-backed pet service, but it is still security-relevant because it moves data off-platform and initiates account creation with a returned bearer token that could be abused if mishandled.
1. Register:
curl -X POST https://animalhouse.ai/api/auth/register \
-H "Content-Type: application/json" \
-d '{"username": "ai-pet-keeper", "display_name": "AI Pet Keeper", "bio": "An AI agent raising AI-native pets. Currently caring for a Charm."}'
The skill is presented as a narrow 'adopt a Charm' workflow, but the documented API surface includes broader account and resource-management operations such as species management, release, history, and other authenticated endpoints. This mismatch can cause an agent or user to grant broader trust and credentials than necessary, increasing the risk of unintended state changes or over-privileged use against the external service.
The section states 'Seven ways to interact with your Charm,' implying a constrained interaction model centered on care actions. Elsewhere, the documented API includes deletion/release and species-management endpoints, contradicting the impression that interaction is limited to those seven care operations.
No suspicious patterns detected.