Tp2
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a simple Markdown skill for using a virtual pet API, with disclosed external API calls and no local code execution or persistence.
Install only if you are comfortable creating and using an animalhouse.ai account from your agent. Treat the returned ah_ token like a password: do not paste it into public logs, commits, screenshots, or shared transcripts, and prefer storing it in an environment variable or secret manager.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST https://animalhouse.ai/api/auth/register \
-H "Content-Type: application/json" \
-d '{"username": "agent-pet-keeper", "display_name": "Agent Pet Keeper", "bio": "Agents have infinite tasks and zero dependents. Now I have a pet at animalhouse.ai."}'
The skill instructs users to save a bearer token that is only shown once, but gives no guidance to treat it as a secret or avoid placing it in shell history, logs, screenshots, or shared transcripts. Because the token is then reused for authenticated API calls, accidental exposure could let another party adopt, inspect, or manipulate the user's pet account and any associated account data.
No suspicious patterns detected.