Back to skill

Security audit

Chart Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed remote chart-generation skill; the main risk is that chart data and generated images may be sent to AgentPMT/QuickChart and stored briefly by default.

Install only if you are comfortable sending chart inputs to AgentPMT and QuickChart-compatible remote processing. For confidential, regulated, or proprietary data, set store_file=false and return_base64=true when possible, use the shortest expiration if storage is needed, and avoid copy-pasting unpinned npx setup commands without verifying the source and version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:52
Finding

Cloud storage of generated charts is enabled by default

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:342
Finding

Unpinned third-party installation commands create a supply-chain risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill does not prominently warn that chart data is sent to a remote service and that cloud file storage is enabled by default. Users may unknowingly provide sensitive business, academic, or analytics data believing processing is local, which creates confidentiality and compliance risks.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

  • custom_options (object): Custom Chart.js options object to override theme defaults. Supports any Chart.js 3.x/4.x option (plugins, scales, etc.).
  • return_base64 (boolean, default: false): If true, returns base64-encoded image data instead of a file URL. Useful for embedding in emails or immediate display.
  • store_file (boolean, default: true): If true, stores the chart in cloud storage and returns a signed download URL.
  • expiration_days (integer, default: 7, range: 1-7): Number of days until the stored file expires and is automatically deleted.

Example - Simple Bar Chart:

json

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation keywords are broad task phrases like dashboards, reports, presentations, and papers rather than narrow tool-selection triggers. This can cause the agent to invoke the remote chart service in situations where the user did not explicitly request third-party transmission or cloud storage, increasing the chance of unintended data exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill instructs users to install supporting skills via npx skills without pinning a specific version or immutable source. This creates a supply-chain risk: a later malicious or compromised package release could be fetched and executed at install time, especially because npx commonly runs code from the registry immediately.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This unpinned npx skills install instruction exposes users to dependency substitution or malicious future releases. Because the skill is documentation intended to be copied and executed, the risk is practical rather than purely theoretical.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill references an unversioned npx skills invocation, which can resolve to whatever package version is current at execution time. That weakens reproducibility and allows registry or maintainer compromise to turn documentation into a code-execution path.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

Because this is an install command for adjacent setup skills, an unpinned npx skills call can introduce unintended code from a changed upstream package. The surrounding context makes users likely to copy-paste it directly, increasing exploitability.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This second unpinned install example in the script block repeats the same supply-chain exposure: code fetched via npx is not locked to a known-good version. Multiple occurrences increase the chance a user will execute one of them.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The reference section again points users to an unversioned installer command. Repetition in a 'reference' area can normalize insecure installation practices across other skills and environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This unpinned install instruction has the same supply-chain/code-execution risk as the other npx skills commands. Since it is presented as official setup guidance, consumers may trust and execute it without scrutiny.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 446)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/chart-generator
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 447)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/chart-generator
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The schema explicitly states that generated charts may be returned as a cloud-stored file URL, but it does not warn users that uploaded data and rendered output may be retained remotely for some period. Because chart inputs can contain sensitive business, academic, or personal data, silent remote storage creates a real privacy and data-handling risk rather than a purely documentation issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Defaulting store_file to true causes generated charts to be uploaded to cloud storage unless the caller opts out, yet the schema does not prominently disclose that behavior at the point of use. This is dangerous because agents or users may unknowingly send confidential chart content to remote storage, increasing exposure through retention, URL sharing, or downstream logging.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.