Tp2
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent KWDB text-to-SQL helper, with database access risks that are disclosed and tied to its purpose.
Install this only for KWDB workflows and connect it to an MCP server/account that is authorized for the target databases. Review generated SQL before approving execution, especially write, DDL, DROP, DELETE, UPDATE, or ALTER statements, and avoid broad schema discovery where database names or table definitions are sensitive.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The trigger 'query KWDB database' is broad enough that generic database or SQL-related requests may invoke this skill even when the user did not intend KWDB-specific behavior. That can cause misrouting, incorrect SQL generation, and unsafe follow-on actions such as schema discovery or execution prompts against the wrong environment.
The trigger 'write SQL for KWDB' is still ambiguous because users may request SQL writing in mixed-database contexts or without intending this skill to take over execution-oriented workflow. Overbroad activation increases the chance that the skill applies KWDB-specific syntax, schema assumptions, or execution steps to unrelated requests.
The workflow instructs the agent to ask the user for the database name using a Chinese-only prompt, and similar mandated Chinese prompts appear elsewhere. This imposes a language choice without offering the user an opt-in or alternative, which is a natural-language policy concern.
This fallback step requires asking for schema information using a Chinese-only prompt. Because the file does not state that the skill is region-specific or that the user can choose the language, it effectively enforces a locale without consent.
The execution confirmation step tells the agent to prompt in Chinese and accept Chinese response words such as "是" and "执行". This is a language policy issue because it requires a specific language/locale without user opt-in or a documented regional constraint.
The "Use for" section lists only Chinese phrases as the activation/use cues, which imposes a language-specific interaction pattern. The file does not offer alternative languages, user opt-in, or any justification that this skill is intentionally limited to a Chinese-language environment.
The file uses Chinese-only natural-language examples such as "最新温度" and "最近一条记录" to describe when the skill should be used. This imposes a specific language context without user opt-in or a documented justification that the skill is intended only for a Chinese-language environment.
The guidance instructs the agent to enumerate databases, tables, and full table definitions to generate SQL, but it does not require a user-consent or least-privilege check before exposing potentially sensitive schema metadata. In an MCP-integrated environment, schema names and DDL can reveal business context, identifiers, or sensitive data structure, so automatic discovery increases unnecessary metadata exposure even if only read-only commands are used.
The entry for clock_timestamp() contains the Chinese term 变化, while the rest of the document is in English. This introduces a language inconsistency without offering a language choice or documenting a justified locale-specific requirement.
The 'Natural Language Mapping' table presents all natural-language examples in Chinese, which effectively imposes a specific language/locale in the skill content. The file does not indicate that Chinese is optional, user-selectable, or required for a documented region-specific reason.
The routing rules and keyword mappings explicitly hard-code both Chinese and English trigger terms, implying language-specific behavior, but the document does not state whether users may use other languages or whether the skill is intentionally limited to these locales. Under the language/locale policy check, this can be read as forcing a specific set of languages without opt-in or justification.
This markdown reference is primarily written in English, but the data type table, warning block, and natural-language mapping switch to Chinese. The file does not indicate that the bilingual or Chinese-specific content is intentional, optional, or limited to a particular locale, which can violate language-choice expectations under the policy.
This markdown includes user-facing trigger and usage text in Chinese while other sections are in English, but it does not indicate that the skill is intended only for Chinese-speaking users or provide an opt-in language choice. Under the policy, forcing or assuming a specific language without user choice is a natural-language policy concern.
Several explanatory headings, table entries, and notes in the latter half of the file are written only in Chinese, while the rest of the document is in English. There is no explicit justification that this is a region-specific or Chinese-only skill, so the file imposes a language constraint without opt-in.
No suspicious patterns detected.