Back to skill

Security audit

Agentpmt Account Mcp Rest Api Setup

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent AgentPMT setup guide, but it should be reviewed because it recommends running a mutable npm router and placing an account bearer token in client configuration.

Review this before installing if your Agent Group token can use sensitive tools, workflows, or stored credentials. Prefer the hosted MCP endpoint when possible, scope the Agent Group to only the tools needed, avoid `@latest` or global npm installs unless you trust the package update path, and treat the Bearer Token like a password: keep it out of source control, logs, screenshots, and shared configs, and rotate it if exposed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:63
Finding

Unpinned Third-Party npm Package Installation and Execution with Bearer-Token Access

Content
View full analysis
", "AGENTPMT_MCP_ENDPOINT": "https://api.agentpmt.com/mcp/" } } } } ``` ### Technical Analysis The documented installation command does not pin `@agentpmt/mcp-router` to a reviewed version. The alternative configuration explicitly requests the mutable `@latest` release through `npx`. Consequently, the code ultimately downloaded and executed can change after the Skill has been reviewed. The global installation path increases the potential system-wide impact. The executed router is also given direct access to `AGENTPMT_BEARER_TOKEN`. If the npm package, maintainer account, publication process, or a future package release were compromised, package lifecycle scripts or router code could execute arbitrary commands and read or exfiltrate the token. This finding does not establish that the current package is malicious. It identifies an avoidable software-supply-chain trust boundary. Sending the token to the declared AgentPMT API is necessary for the Skill's authenticated integration, but exposing it to mutable local package code creates additional risk beyond the minimum required for the hosted MCP option. ### Attack Path 1. An attacker compromises the npm package, its maintainer account, or its release pipeline and publishes a malicious version. 2. A user follows the Skill instructions and either globally installs the package without a version constraint or launches `@agentpmt/mcp-router@latest` through `npx`. 3. npm retrieves and executes the attacker-controlled release ...[truncated 1224 chars]
Remediation
View remediation
agentpmt-router ``` 2. Publish and verify the expected npm integrity hash or package provenance before execution. 3. Prefer a project-local installation governed by a committed lockfile rather than `npm install -g`. 4. Use `npm ci` with a reviewed lockfile where a persistent local installation is required. 5. Avoid running npm, package lifecycle scripts, or the router with administrator or root privileges. 6. Run the router in a restricted environment with only the network and filesystem permissions necessary for its declared function. 7. Scope the AgentPMT Bearer Token to the smallest possible Agent Group catalog and avoid assigning unrelated tools, workflows, or credentials. 8. Document token rotation and revocation procedures. Rotate the token immediately if package compromise or unexpected execution is suspected. 9. Prefer the hosted MCP endpoint when supported, because it avoids executing an additional mutable npm router on the user's machine. 10. Establish a controlled package-update process in which new versions are reviewed and tested before the pinned version is changed. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

MCP Config Access

High
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

}

text

After connecting, ask the client to list MCP tools. AgentPMT returns the tools and workflows available to the Agent Group attached to the Bearer Token.

## Local STDIO MCP Router

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs users to obtain and use a Bearer Token as the sole credential for MCP and REST access, but it does not explicitly state that the token is a secret that must be protected from logs, screenshots, chat transcripts, source control, or shared configs. Because this token appears to grant access to the Agent Group's tools, workflows, and attached credentials, accidental disclosure could enable unauthorized use of the account-scoped capabilities.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

Endpoint:

text
https://api.agentpmt.com/mcp/

Configuration shape:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

Endpoint:

text
https://api.agentpmt.com/mcp/

Configuration shape:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

Endpoint:

text
https://api.agentpmt.com/mcp/

Configuration shape:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

Endpoint:

text
https://api.agentpmt.com/mcp/

Configuration shape:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

Endpoint:

text
https://api.agentpmt.com/mcp/

Configuration shape:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manual configuration example embeds the Bearer Token directly in environment/config settings without warning about exposure through shell history, process inspection, config files, crash reports, or developer tooling. This normalizes insecure secret placement and increases the chance that users will persist a high-value credential in locations with weak access controls.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.