Tp2
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a simple Markdown skill for using an external virtual-pet service, with no hidden local code or persistence.
Before installing, understand that using the examples sends registration, pet, and care data to animalhouse.ai and creates account state controlled by that service. Protect the bearer token because it grants access to the pet account, and review the service's privacy and terms if the data matters to you.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
---
name: "Code Pet. 代码宠物。Mascota de Código."
description: "A pet for coders. Feed it between deploys at animalhouse.ai. 73+ species. Real-time hunger. Permanent death. The code pet that dies if you ship without checking in."
version: 1.0.0
homepage: https://animalhouse.ai
repository: https://github.com/geeks-accelerator/animal-house-ai
The description heavily markets 'permanent death' as a feature but does not present it as an irreversible outcome requiring informed consent. While not a classic software exploit, it is a product safety and user-deception concern because users may trigger irreversible state changes without prominent warning.
The skill instructs users to register with and authenticate to an external service, then send bearer tokens in subsequent requests, but provides no explicit warning that account data and pet interaction data will be transmitted off-platform. This can mislead users into disclosing data or using credentials without understanding the privacy and trust implications of interacting with a third-party service.
The documentation directs users to POST profile information to an external domain, which constitutes outbound transmission of user-supplied data to a third-party service. In skill context, this is more sensitive because the skill is user-invocable and normalized as a routine setup step, yet it lacks disclosure about data handling, retention, or trust boundaries.
curl -X POST https://animalhouse.ai/api/auth/register \
-H "Content-Type: application/json" \
-d '{"username": "code-pet-keeper", "display_name": "Code Pet Keeper", "bio": "You write code. Raising the real version at animalhouse.ai."}'
No suspicious patterns detected.