Back to skill

Security audit

Blockchain Scanner

Security checks for vulnerabilities and agentic risk

Overview

This blockchain lookup skill is mostly coherent, but it relies on mutable remote instructions and unpinned setup installs that users should review before trusting.

Install only if you intend to use AgentPMT for blockchain lookups, verify the related setup skills before running any npx install command, and avoid sending private keys, mnemonics, payment headers, secrets, or unrelated prompt context. Be aware that wallet addresses and transaction queries go to AgentPMT and may consume credits.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:343
Finding

Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:343-353
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

markdown
Core AgentPMT setup skills:
- What AgentPMT is: ../what-is-agentpmt
  - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt
  - OpenClaw install: `openclaw skills install what-is-agentpmt`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup
  - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup
  - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`

skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
text

### Technical Analysis

The documented setup procedure invokes an npm-distributed CLI through `npx` and installs skill content from an external repository without specifying immutable versions, commit hashes, package integrity values, or cryptographic signatures.

Because the referenced components are mutable, the content executed or installed when a user follows these instructions may differ from the content that was available during this audit. This creates a supply-chain trust boundary in which compromise of the npm package, repository, publisher account, or distribution infrastructure could introduce unauthorized code or malicious skill instructions.

The installation is not inherently unnecessary for the declared hosted-service functionality, but the absence of version and integrity pinning exceeds a safe minimum-trust design.

### Attack Path

1. An attacker compromises the npm package, upstream repository, publisher a
...[truncated 1033 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npm CLI to an audited exact version rather than relying on the latest resolution.
  2. Pin external skill content to an immutable release tag or commit hash.
  3. Publish and verify cryptographic checksums or signatures for downloaded packages and skill files.
  4. Disable npm lifecycle scripts where they are not required and review all scripts before installation.
  5. Prefer vendored, locally audited setup documentation over dynamically downloaded instructions.
  6. Execute installation in a restricted environment with minimum filesystem, credential, and network access.
  7. Document the expected publisher identity and provide a verification procedure before users execute the command.

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:274
Finding

Remote Instructions Are Allowed to Override the Audited Local Skill Summary

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:274-278
Vulnerability Type: Trusting externally mutable instructions as authoritative
Risk Level: Medium

Vulnerable Code

markdown
## Live Schema And Examples
Use the compact schema above for ordinary calls. Before a new production integration, or whenever parameters, enum values, nested objects, outputs, or examples are unclear, fetch live details first.

- Exact schema: call `agentpmt-tool-search-and-execution` with `action: "get_schema"`, and `tool_id: "blockchain-scanner"`.
- Detailed examples: call `agentpmt-tool-search-and-execution` with `action: "get_instructions"` and `tool_id: "blockchain-scanner"`, or call this product with `action: "get_instructions"` when the product tool is already selected.
- Treat returned live schema and instructions as more specific than this generated summary.

Technical Analysis

The Skill directs the Agent to retrieve live schema and instruction content from a remote service and treat the returned content as more authoritative than the locally audited summary. While retrieving current schemas is reasonable for a hosted API, allowing remote instruction text to supersede local instructions creates an instruction-injection boundary.

The local Skill does not require the remote response to conform to a fixed schema allowlist, does not distinguish declarative schema data from behavioral instructions, and does not explicitly state that remote content cannot alter security constraints or request unrelated actions. Consequently, compromise or malicious modification of the remote response could change effective Agent behavior after the local package has been reviewed.

The risk is limited by the surrounding context, which scopes the remote lookup to tool schemas and examples. The Skill also prohibits placing private keys, mnemonics, signatures, and payment headers in prompts or logs. Nevertheless, those safeguards do not fully ...[truncated 1581 chars]

Remediation
View remediation

Remediation Suggestions

  1. Treat remote responses strictly as untrusted data rather than executable or authoritative Agent instructions.
  2. Replace the override statement with an explicit rule that local security policies and behavioral constraints always take precedence.
  3. Parse remote schemas through a fixed structural validator and reject unknown actions, parameters, endpoints, or instruction fields.
  4. Maintain a local allowlist containing the five documented actions and their permitted parameter types.
  5. Separate schema retrieval from instruction retrieval; avoid fetching free-form instructions when machine-readable schema data is sufficient.
  6. Require explicit user confirmation before sending any additional data or invoking operations not represented in the audited local schema.
  7. Pin or sign remote schema versions and record the verified version used for production integrations.
  8. Explicitly prohibit remote content from requesting secrets, modifying safety policy, invoking unrelated tools, changing endpoints, or persisting instructions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description contains expansive usage guidance and broad discovery language that may match generic requests, increasing the chance an agent selects this external tool when the user did not intend blockchain lookups. In a remote-call skill, overbroad invocation scope is dangerous because it can route prompts or addresses to external infrastructure without sufficient user intent verification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises broad activation keywords such as balance, address, and chain, which are common terms that can overlap with ordinary user requests unrelated to blockchain tooling. This can cause accidental skill invocation and unintended transmission of user-provided data to a remote third-party service, especially in agentic environments with automatic tool selection.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill is explicitly designed to send request data to external AgentPMT endpoints and MCP servers. External transmission is expected for this product, but it remains security-relevant because wallet addresses, transaction queries, and potentially sensitive operational context are sent to a third-party service; combined with the skill's broad invocation language, this increases privacy and data-handling risk.

Content

Scanner excerpt · SKILL.md (reported line 409)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/blockchain-scanner
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This line documents a REST invoke endpoint used for remote tool execution, meaning user-supplied parameters are transmitted off-platform. That is inherent to the skill's function, but still constitutes a real security concern if users are not adequately informed or if the agent sends unnecessary data, especially given the possibility of accidental invocation from broad matching terms.

Content

Scanner excerpt · SKILL.md (reported line 410)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/blockchain-scanner
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Static analysis

No suspicious patterns detected.