Back to skill

Security audit

agent-context-manager

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate AgentPMT document-management skill, but it can change persistent business context documents and gives under-scoped setup and activation guidance.

Install only if you intend to connect agents to AgentPMT and store context documents there. Avoid putting secrets or highly confidential material in document bodies unless your organization has approved AgentPMT for that data, prefer pinned or reviewed setup installs over the unpinned npx examples, and require clear human approval before create, update, archive, or restore actions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Remote Skill Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:14, SKILL.md:153-163, and SKILL.md:212-213
Vulnerability Type: Unpinned third-party Skill installation
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md:14:

text
If the current date is more than 7 days after the last updated date, reinstall this skill from skills.sh or ClawHub before relying on endpoints, schemas, setup steps, or examples.

SKILL.md:153-163:

markdown
- What AgentPMT is: ../what-is-agentpmt
  - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt
  - OpenClaw install: `openclaw skills install what-is-agentpmt`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup
  - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup
  - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`

skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
text

`SKILL.md:212-213`:

```markdown
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)

Technical Analysis

The installation commands retrieve third-party Skill content without specifying an immutable release, commit hash, or integrity digest. The instructions also recommend reinstalling the Skill when ...[truncated 1795 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every referenced package and Skill to a reviewed immutable version or commit hash.
  2. Publish and verify cryptographic integrity hashes or signatures before installation.
  3. Replace the automatic seven-day reinstall instruction with a controlled update process that presents and reviews upstream changes before installation.
  4. Pin the package that provides the npx command rather than allowing dynamic resolution of its latest release.
  5. Use lockfiles or an equivalent dependency manifest where supported.
  6. Run installation in a sandbox with minimal filesystem, network, credential, and environment-variable access.
  7. Maintain an approved dependency inventory and periodically verify publisher ownership, signatures, and source provenance.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The top-level description says the skill should be used when an agent 'needs agent context manager,' but does not define clear boundaries for activation. Ambiguous invocation guidance can cause over-selection of the skill and accidental routing of user content into an external document-management system.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation keywords are excessively broad and contain long generic natural-language phrases that overlap with ordinary business requests. That can cause the skill to trigger in situations where users did not intend external tool usage, increasing the chance of unnecessary data exposure or unintended state-changing actions against the remote service.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs users to run npx skills add ... without pinning an exact package version or integrity mechanism. That creates a supply-chain risk: future package changes or a compromised upstream package could cause users to install and trust unintended code or skill content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This line repeats an unpinned npx skills installation flow, which allows whatever version is current at execution time to be fetched and run. In a skill ecosystem, that weakens reproducibility and exposes users to package substitution or malicious updates.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

An unversioned npx skills command is a real supply-chain hazard because it delegates trust to the latest remotely served package at install time. If the package or dependency chain is compromised, users may install malicious tooling or altered skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This is another instance of the same unpinned install pattern, which increases attack surface through remote package retrieval without immutability. Repeated unsafe install guidance makes exploitation more likely across users following the documentation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skills.sh install instruction again uses npx skills without version constraints, enabling non-deterministic code execution from upstream sources. Because this is presented as setup guidance, users may execute it directly with high trust.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This repeated floating install command preserves the same supply-chain weakness: execution depends on mutable external package state. In documentation for agent tooling, that can directly lead to compromised local environments or poisoned skill installations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill explicitly directs agents to send requests to external AgentPMT endpoints, which is a real external transmission path. Given the tool manages context documents that may contain SOPs, pricing rules, policy documents, and other sensitive organizational knowledge, accidental or excessive data transfer to the remote service could expose confidential information.

Content

Scanner excerpt · SKILL.md (reported line 215)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/agent-context-manager
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This line identifies the REST invoke endpoint, confirming that skill use results in data being sent off-platform. In the context of an agent context manager, the transmitted content may include mission-critical instructions or internal policies, so unintended external transmission is materially sensitive even if the product is legitimate.

Content

Scanner excerpt · SKILL.md (reported line 216)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/agent-context-manager
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The schema exposes an archive action that permanently changes document state, but the description does not warn callers that the action is destructive or may hide operationally important context from workflows. In an agent-facing skill, missing safety messaging increases the chance an LLM or user invokes the action casually, causing unintended loss of availability or confusion even if the backend enforces authorization and CAS checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The restore-version action can overwrite the current document state with an older snapshot, but the schema does not warn that this may discard newer edits or revert important policy/context data. In a system intended to store reusable agent instructions, an accidental restore could propagate outdated or unsafe guidance across dependent agents and workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.