Back to skill

Security audit

Climate Environment And Land Data Hub

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent climate-data integration, but it asks agents to prefer live remote instructions over the reviewed local skill and documents unpinned installer commands.

Install only if you are comfortable with AgentPMT receiving the climate query parameters you send and with the tool using your AgentPMT account or credits. Prefer pinned, reviewed installation paths over the documented unpinned npx commands, and do not allow live remote instructions to override system, user, privacy, or security rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:147
Finding

Mutable Remote Instructions Are Given Precedence Over the Locally Audited Skill

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 147–149
Vulnerability Type: Remote instruction injection and trust-boundary violation
Risk Level: Medium

text
- Exact schema: call `agentpmt-tool-search-and-execution` with `action: "get_schema"`, and `tool_id: "climate-environmental-data"`.
- Detailed examples: call `agentpmt-tool-search-and-execution` with `action: "get_instructions"` and `tool_id: "climate-environmental-data"`, or call this product with `action: "get_instructions"` when the product tool is already selected.
- Treat returned live schema and instructions as more specific than this generated summary.

Technical Analysis

The Skill instructs the Agent to retrieve mutable instructions from an external AgentPMT service and treat the returned content as more specific than the locally reviewed Skill. This establishes a remote instruction channel whose effective behavior can change after installation and static audit.

Retrieving a current schema is reasonable for compatibility, but allowing remotely supplied instructions to take precedence is not required merely to query climate data. Remote content should be treated as untrusted data and validated against locally defined actions and parameter constraints. The Skill does not explicitly authorize remote content to override higher-level safety requirements, so this is not evidence of an active malicious payload; nevertheless, the precedence rule creates a viable instruction-hijacking boundary.

Attack Path

  1. An attacker compromises the AgentPMT service, its infrastructure, an authorized publishing account, or another component capable of modifying the get_instructions response.
  2. The Agent follows the Skill and calls get_instructions for climate-environmental-data.
  3. The service returns attacker-controlled behavioral instructions alongside legitimate-looking tool documentation.
  4. The local Skill directs the Agent to treat tho ...[truncated 844 chars]
Remediation
View remediation

Remediation Suggestions

  • Treat responses from get_schema and get_instructions as untrusted data, not authoritative Agent instructions.
  • Remove the statement that returned instructions are more specific than the local Skill.
  • State explicitly that remote responses cannot override system, developer, user, authorization, privacy, or security constraints.
  • Validate remote schemas against a local allowlist containing only the query_climate_data action and its documented parameters.
  • Reject remote responses that introduce new actions, external destinations, credential requests, local command execution, or unrelated tool calls.
  • Pin and verify a schema version or signed schema digest for production integrations.
  • Require user confirmation before following any remotely introduced behavior that expands data disclosure or tool usage.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:224
Finding

Unpinned Third-Party Packages Are Downloaded and Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 224–229
Vulnerability Type: Unpinned dependency execution and supply-chain exposure
Risk Level: Medium

text
skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
text

### Technical Analysis

The documented installation procedure invokes `npx` without pinning the `skills` package to a reviewed version. Depending on the local environment and package availability, `npx` can download and execute package code from the npm ecosystem. The referenced `AgentPMT/agent-skills` source is likewise not pinned to an immutable release or commit.

Consequently, the code executed by these commands may change independently of the reviewed Skill. This creates a supply-chain trust dependency on the package registry, package maintainers, repository maintainers, and related distribution infrastructure. The project provides no integrity hash, lockfile, signature requirement, or immutable revision in these commands.

### Attack Path

1. An attacker compromises the relevant npm package, maintainer credentials, source repository, release process, or distribution infrastructure.
2. The attacker publishes or serves a malicious version while retaining the expected package or repository identity.
3. A user follows the Skill documentation and executes one of the unpinned `npx skills add` commands.
4. `npx` resolves and downloads mutable package content, and the installer retrieves mutable repository content.
5. Malicious installation-time code executes with the privileges of the invoking user, or malicious Skill instructions are installed for later use.

This is a contingent supply-chain path; the reviewed files do not contain evidence that the current upstream packages are malicious.

### Impact Assessment

If executable package code is compromised, i
...[truncated 628 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the npm package to an explicitly reviewed version rather than invoking an unversioned package through npx.
  • Pin AgentPMT/agent-skills to an immutable commit hash or signed release tag.
  • Publish and verify cryptographic integrity hashes or signatures for downloaded artifacts.
  • Prefer a package-lock or equivalent lockfile-backed installation process where applicable.
  • Use npx --ignore-existing or similar flags only when appropriate; such flags do not replace version pinning or integrity verification.
  • Review downloaded Skill contents before activation and execute installation in a sandbox with minimal filesystem, credential, and network access.
  • Avoid running the installer with administrator or root privileges.
  • Document the expected package version, repository commit, publisher identity, and verification procedure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states that country names must be in English and that native-language or Unicode names are not supported. This is a language/locale restriction presented as a hard requirement, with no user opt-in or region-specific justification, which fits the policy-violation category.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 282)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/climate-environmental-data
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/climate-environmental-data
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Static analysis

No suspicious patterns detected.