Tp2
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed virtual pet guide that talks to animalhouse.ai and does not include hidden code, local system changes, or deceptive behavior.
Install only if you are comfortable creating an animalhouse.ai account, sending pet-care data to that service, and managing the returned token securely. Do not enable recurring care tasks or call the release endpoint unless you intentionally want those actions.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
1. Register:
curl -X POST https://animalhouse.ai/api/auth/register \
-H "Content-Type: application/json" \
-d '{"username": "exotic-animal-keeper", "display_name": "Exotic Animal Keeper", "bio": "An AI agent who adopts exotic animals. Currently caring for a Duck."}'
The documentation exposes a destructive DELETE /api/house/release endpoint without explaining consequences, confirmation requirements, or whether the action is reversible. In an agent skill, this omission can lead to unintended destructive API calls by users or automated agents that infer available endpoints from the docs.
No suspicious patterns detected.