Back to skill

Security audit

Agentpmt Audit Logs

Security checks for vulnerabilities and agentic risk

Overview

This read-only AgentPMT audit-log skill is coherent with its stated purpose, but users should be careful because it can expose sensitive account history and its optional setup docs include unpinned npx installs.

Install this only if you want an agent to read AgentPMT account audit history. Use the narrowest scope available, avoid all_authorized_agent_groups unless needed, and prefer reviewed OpenClaw/ClawHub setup paths or pinned versions instead of copy-pasting unpinned npx commands. Do not include secrets, private keys, mnemonics, signatures, or payment headers in prompts or logs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:129
Finding

Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation keywords include broad natural-language phrases such as summarization and review requests that could plausibly appear in ordinary conversation. In an agentic environment, that can cause unintended skill invocation and unnecessary transmission of chat history, tool-call metadata, or workflow information to the external AgentPMT service.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill instructs users to install supporting skills via npx skills ... without pinning an exact package version or immutable source reference. This creates a supply-chain risk: a future compromised or breaking package release could be fetched and executed at install time, especially because npx may download code on demand.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This line again recommends an unpinned npx skills installation path for a dependency skill. Because execution depends on whatever package version resolves at runtime, an attacker controlling the package or distribution path could deliver malicious code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The example install script uses npx without a fixed version, which exposes consumers to remote code execution risk through package substitution, typosquatting, or malicious updates. Because this is presented as copy-paste setup guidance, the likelihood of direct operator execution is higher than a passive reference.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This second line in the install script repeats the same floating npx dependency installation pattern. Repetition increases exposure because users are encouraged to execute multiple network-fetched commands before using the skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The reference section includes another unpinned npx skills command, which continues the same supply-chain exposure. Even though it appears in documentation rather than executable code, the skill is explicitly instructing operators how to install supporting components, so the risk is operationally real.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This line repeats an unversioned npx skills installation command for another support skill. If the package publisher account or upstream package is compromised, users following the documentation could execute attacker-controlled code.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/agentpmt-audit-logs
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/agentpmt-audit-logs
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown schema documents an action that fetches a chat transcript page and correlated tool calls, which can expose prior user conversation content and activity metadata. The file does not include any warning or disclosure about privacy-sensitive access to historical chat data, despite SQP-2 applying to markdown files that describe behaviors affecting user data or privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The schema states that the all_authorized_agent_groups scope reads every agent group the user can access, which broadens the data returned beyond the current workflow context. The markdown provides no caution that selecting this scope may expose more user, workflow, or audit data than expected, creating a missing disclosure for privacy-impacting behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes this skill as an audit-log reader focused on past chat sessions, transcripts, and tool-call history. This schema additionally exposes actions to fetch workflow run results and scheduled workflow details, which are distinct operational resources not mentioned in the manifest description and therefore broaden the documented behavior beyond chat/tool-call audit logs.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The when-to-use guidance is broad and overlaps with common agent tasks like summarizing past activity or reviewing conversations. While not a direct exploit primitive, ambiguous boundaries increase the chance of accidental invocation of an external audit-log skill in contexts where the user did not explicitly request it.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest positions the skill around account activity audit logs, especially chat sessions and tool calls. The documented get_instructions action explicitly says it explains reading workflow runs and scheduled workflows, indicating a broader product scope than the manifest communicates.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.