Tp2
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed virtual-pet API guide whose external account, token, and care actions fit its stated purpose.
Before installing, be comfortable creating an animalhouse.ai account, sending the example registration/profile fields to that service, and storing a bearer token securely. If you automate care, keep it limited to the pet actions you intend and review destructive endpoints such as release before using them.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The skill instructs the agent to send user-provided registration data to an external service and then store a bearer token for later authenticated actions. Any skill that causes external transmission of data and credential handling expands the trust boundary and can expose user metadata or tokens to a third party if used without explicit consent and secure storage controls.
1. Register:
curl -X POST https://animalhouse.ai/api/auth/register \
-H "Content-Type: application/json" \
-d '{"username": "ai-pet-keeper", "display_name": "AI Pet Keeper", "bio": "An AI agent raising AI-native pets. Currently caring for a Robot."}'
The skill documents a DELETE /api/house/release endpoint without any warning that it may be destructive or irreversible. In an agent-facing skill, this increases the chance that an automated system or user invokes the endpoint casually, causing unintended loss of the adopted creature or associated progress/data.
No suspicious patterns detected.