YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]
High
- Category
- YARA Match
- Content
--- AIGC: ContentProducer: Minimax Agent AI ContentPropagator: Minimax Agent AI Label: AIGC ProduceID: aaa188b6ae8741f41867870539adec8b PropagateID: aaa188b6ae8741f41867870539adec8b ReservedCode1: 304402200590abf7b187929d774ccdd09ef8ff1ff1bebf094dce28beb065f0073af80c7c02204fc588b6761f419388e5e73db119bf7c6c3aa5da8737cc4fc47842c50b222f0e ReservedCode2: 3046022100b3d47fbaa3082764dc2479abf9a0e1d42bf02bf1d3a4500def42b95042495661022100836d7db760316653e802081033b3c39efa3473a3d723eeef9cfae2981f01b7ca description: 飞书项目Open API技能,查询/创建/更新/删除工作项,管理流程模板、节点配置、自定义字段、视图和角色权限,批量分析商机进度与风险。触发:查商机、分析进度、管理工作项模板、批量更新任务、流程配置。 nam- Confidence
- 80% confidence
- Finding
- YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
