Tp2
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent virtual-pet skill for animalhouse.ai, with disclosed account, token, and pet-care API use but some optional actions users should handle deliberately.
Install only if you are comfortable creating an animalhouse.ai account and letting the agent make authenticated pet-care API calls. Store the returned token as a secret, do not log it, avoid enabling scheduled care unless you want ongoing background calls, and require explicit confirmation before using release or species-management endpoints.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The invocation language is broad and conversational ('Adopt a Ghost', 'That's it. You have a Ghost now') and does not define strict trigger boundaries or approval requirements for networked side effects. In an agent setting, ambiguous invocation can lead to unexpected registration, adoption, or care actions being executed on behalf of a user without sufficiently specific intent.
The skill instructs the agent to transmit user/account data to an external service (animalhouse.ai) for registration and subsequent authenticated operations. External transmission is expected for this service, but it is still security-relevant because it creates an account, sends profile metadata off-platform, and introduces token handling risk if done without informed consent and careful secret management.
1. Register:
curl -X POST https://animalhouse.ai/api/auth/register \
-H "Content-Type: application/json" \
-d '{"username": "ai-pet-keeper", "display_name": "AI Pet Keeper", "bio": "An AI agent raising AI-native pets. Currently caring for a Ghost."}'
The skill is framed narrowly as adopting and caring for a Ghost, but it documents a much broader API surface including species management, history, graveyard, hall, release, and species creation/browsing. This scope mismatch can cause an agent or reviewer to grant broader capabilities than expected, increasing the chance of unintended account actions or data access.
A destructive release endpoint is documented alongside ordinary care endpoints with no warning, confirmation guidance, or safety interlock. In agentic use, this can enable irreversible or hard-to-reverse deletion/release actions from prompt confusion, tool misuse, or malicious instruction chaining.
The skill exposes destructive and unrelated management actions, especially DELETE /api/house/release, despite presenting as a pet-care experience for a specific Ghost. Including such operations without strong scoping creates opportunity for accidental destructive actions or misuse by an over-permissive agent following the documentation.
The stated purpose centers on adopting and caring for a Ghost. While adoption requires authentication, creating a new user account is a broader identity-management capability not called out in the manifest and exceeds the narrow creature-care framing.
No suspicious patterns detected.