YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]
- Category
- YARA Match
- Confidence
- 80% confidence
- Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
- Content
python "学习": "📚", "运动": "🏃", "跑步": "🏃", "游泳": "🏊", "唱歌": "🎤", "跳舞": "💃", # 时间 "早上": "🌅", "中午": "☀️", "晚上": "🌙", "今天": "📅", "明天": "📅", "周末": "🗓️", "假期": "🏖️", "生日": "🎂", "新年": "🧧", # 人物 "男人": "👨", "女人": "👩", "孩子": "👶", "老师": "👨🏫", "医生": "👨⚕️", "朋友": "👯", "家人": "👨👩👧👦", # 英文关键词 "love": "❤️", "happy": "😊", "sad": "😢", "cool": "😎", "fire": "🔥", "ok": "👌", "yes": "✅", "no": "❌", "good": "👍", "bad": "👎", "cat": "🐱", "dog": "🐶", "heart": "❤️", "star": "⭐", "sun": "☀️", } # Emoji -> 文字描述映射 EMOJI_TO_TEXT = { "❤️": "[爱心]", "😊": "[微笑]", "😄": "[开心]", "😂": "[笑哭]", "😢": "[难过]", "😠": "[生气]", "😡": "[愤怒]", "😮": "[惊讶]", "�
