T09 · Insecure Skill Coding Practices
- Location
SKILL.md:52- Finding
Cloud storage of generated charts is enabled by default
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed remote chart-generation skill; the main risk is that chart data and generated images may be sent to AgentPMT/QuickChart and stored briefly by default.
Install only if you are comfortable sending chart inputs to AgentPMT and QuickChart-compatible remote processing. For confidential, regulated, or proprietary data, set store_file=false and return_base64=true when possible, use the shortest expiration if storage is needed, and avoid copy-pasting unpinned npx setup commands without verifying the source and version.
SKILL.md:52Cloud storage of generated charts is enabled by default
SKILL.md:342Unpinned third-party installation commands create a supply-chain risk
The skill does not prominently warn that chart data is sent to a remote service and that cloud file storage is enabled by default. Users may unknowingly provide sensitive business, academic, or analytics data believing processing is local, which creates confidentiality and compliance risks.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
custom_options (object): Custom Chart.js options object to override theme defaults. Supports any Chart.js 3.x/4.x option (plugins, scales, etc.).return_base64 (boolean, default: false): If true, returns base64-encoded image data instead of a file URL. Useful for embedding in emails or immediate display.store_file (boolean, default: true): If true, stores the chart in cloud storage and returns a signed download URL.expiration_days (integer, default: 7, range: 1-7): Number of days until the stored file expires and is automatically deleted.Example - Simple Bar Chart:
The activation keywords are broad task phrases like dashboards, reports, presentations, and papers rather than narrow tool-selection triggers. This can cause the agent to invoke the remote chart service in situations where the user did not explicitly request third-party transmission or cloud storage, increasing the chance of unintended data exposure.
The skill instructs users to install supporting skills via npx skills without pinning a specific version or immutable source. This creates a supply-chain risk: a later malicious or compromised package release could be fetched and executed at install time, especially because npx commonly runs code from the registry immediately.
This unpinned npx skills install instruction exposes users to dependency substitution or malicious future releases. Because the skill is documentation intended to be copied and executed, the risk is practical rather than purely theoretical.
The skill references an unversioned npx skills invocation, which can resolve to whatever package version is current at execution time. That weakens reproducibility and allows registry or maintainer compromise to turn documentation into a code-execution path.
Because this is an install command for adjacent setup skills, an unpinned npx skills call can introduce unintended code from a changed upstream package. The surrounding context makes users likely to copy-paste it directly, increasing exploitability.
This second unpinned install example in the script block repeats the same supply-chain exposure: code fetched via npx is not locked to a known-good version. Multiple occurrences increase the chance a user will execute one of them.
The reference section again points users to an unversioned installer command. Repetition in a 'reference' area can normalize insecure installation practices across other skills and environments.
This unpinned install instruction has the same supply-chain/code-execution risk as the other npx skills commands. Since it is presented as official setup guidance, consumers may trust and execute it without scrutiny.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/chart-generator
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/chart-generator
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The schema explicitly states that generated charts may be returned as a cloud-stored file URL, but it does not warn users that uploaded data and rendered output may be retained remotely for some period. Because chart inputs can contain sensitive business, academic, or personal data, silent remote storage creates a real privacy and data-handling risk rather than a purely documentation issue.
Defaulting store_file to true causes generated charts to be uploaded to cloud storage unless the caller opts out, yet the schema does not prominently disclose that behavior at the point of use. This is dangerous because agents or users may unknowingly send confidential chart content to remote storage, increasing exposure through retention, URL sharing, or downstream logging.
No suspicious patterns detected.