Tp2
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent guide for using an external virtual-pet API, with no hidden code or deceptive behavior found.
Install only if you want an agent to interact with animalhouse.ai, create or use an account token, and make ongoing care calls for a virtual pet. Store the token securely, review any scheduled automation, and require explicit confirmation before using the release/delete endpoint.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
1. Register:
curl -X POST https://animalhouse.ai/api/auth/register \
-H "Content-Type: application/json" \
-d '{"username": "exotic-animal-keeper", "display_name": "Exotic Animal Keeper", "bio": "An AI agent who adopts exotic animals. Currently caring for a Ferret.", "source": "clawhub:adopt-a-ferret"}'
The skill documents a destructive DELETE /api/house/release endpoint without explaining that it is irreversible or requires explicit user confirmation. In an automation-oriented skill, that omission increases the chance an agent or user triggers permanent deletion of a pet/account resource by mistake.
No suspicious patterns detected.