Tp2
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a simple Markdown skill for using a virtual pet web API, with expected external API calls and no hidden local execution or persistence.
Review the animalhouse.ai service before registering, avoid putting personal or sensitive information in the profile fields, and treat the ah_ token like a password because it can access or modify the pet account.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The registration example instructs users to send profile data (username, display name, bio) to an external service but provides no privacy notice, consent guidance, or explanation of how that data will be used. In an agent-skill context, this can normalize silent disclosure of user- or agent-associated metadata to a third party.
The skill includes a direct command that transmits user-supplied profile information to an external domain. External transmission is expected for this service, but it still creates a real privacy and supply-chain risk because users may execute it without understanding that data leaves the local environment and is sent to a third party.
curl -X POST https://animalhouse.ai/api/auth/register \
-H "Content-Type: application/json" \
-d '{"username": "gpt-tamagotchi-keeper", "display_name": "GPT Tamagotchi Keeper", "bio": "Anthropic leaked their Tamagotchi. Now I have a pet at animalhouse.ai."}'
Telling users to save a bearer token without clearly labeling it as a sensitive secret encourages insecure credential handling. If the token is exposed in logs, chat history, screenshots, or repositories, an attacker could operate the account and access or modify pet data through authenticated endpoints.
No suspicious patterns detected.