Tp2
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent finance-document generation skill, with disclosed local file creation and PDF validation side effects users should understand before use.
Install only if you want a skill that can generate local finance-report files and validate presentations with browser automation. Confirm the output directory first, especially because the SKILL.md names a /Users/wdj/WorkBuddy/{session_id} path, and avoid providing confidential company data unless you are comfortable with it being written into generated deliverables.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The README states that mentioning relevant keywords in conversation will automatically trigger the skill, but it does not define clear boundaries for when activation should occur. In a chat environment, broad auto-triggering can cause unintended invocation on incidental mentions, leading to unexpected generation of files or finance outputs without explicit user intent.
The triggering instructions tell users to directly describe their needs for automatic activation, again without precise constraints or disambiguation rules. This increases the chance that normal discussion about finance restructuring or CGMA could unintentionally activate the skill and initiate multi-file output behavior.
The trigger list is extremely broad and overlaps with ordinary finance requests, which can cause unintended skill activation. In a skill that writes files and invokes extra tooling, accidental invocation materially increases the chance of unexpected actions being taken on behalf of the user.
The instruction that users can activate the skill by 'simply describing your needs' creates an ambiguous activation boundary. This makes it easier for normal conversation to unintentionally trigger a multi-step workflow with filesystem writes and auxiliary tool usage.
The skill directs automatic creation of multiple files in a specific local filesystem path without clearly warning the user or obtaining explicit consent. Unprompted local writes are dangerous because they create side effects outside the chat boundary, can overwrite or scatter files, and become more risky when combined with broad activation conditions.
The workflow instructs the agent to use Playwright to generate and validate PDFs, which expands the skill from document generation into browser automation. Browser automation can load active HTML, invoke additional tooling, and increase attack surface, especially when the generated content may incorporate user-controlled material.
The README advertises automatic generation of multiple deliverable files, but it does not clearly warn users at that point that files will be created in the working directory. In agent environments, silent or poorly disclosed file creation can surprise users, clutter workspaces, or overwrite expectations about what the skill is permitted to do.
The skill embeds the author's personal email address and phone number directly in the documentation, creating unnecessary exposure of personal contact data. Even if not directly exploitable for system compromise, this increases privacy, spam, social-engineering, and impersonation risk without being needed for the skill's core finance-deliverable function.
No suspicious patterns detected.