YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]
High
- Category
- YARA Match
- Content
--- name: safe-action description: Before any destructive or irreversible action, run a safety pre-flight — check risks, reversibility, and timing. version: 1.0.0 metadata: openclaw: emoji: "🛡️" homepage: https://agentutil.net always: false --- # safe-action Measure twice, cut once. Before taking destructive, irreversible, or high-stakes actions, this skill runs a three-part safety pre-flight: risk assessment, reversibility check, and timing awareness. Combines three AgentUtil services — think (safety checklists), undo (reversibility intelligence), and context (situational timing) — into- Confidence
- 80% confidence
- Finding
- YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
