YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]
High
- Category
- YARA Match
- Content
--- name: mailsai-email description: Give your agent a real email address it can send from, receive at, and reply in-thread — with an injection scan on every inbound and a dry-run sandbox before anything transmits. version: 1.0.0 metadata: openclaw: requires: env: - MAILS_API_KEY bins: - node primaryEnv: MAILS_API_KEY envVars: - name: MAILS_API_KEY required: true description: Mails.ai API key. Keys beginning mk_test_ run the full pipeline in sandbox mode and never transmit a message. - name: MAILS_BASE_URL required: false descript- Confidence
- 80% confidence
- Finding
- YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
