Back to skill

Security audit

Commerce And Trade Competitiveness Data Hub

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for querying AgentPMT trade data, with disclosed remote API use and a caution around optional unpinned setup commands.

Before installing, confirm you trust AgentPMT and understand that calls go to AgentPMT's hosted service and may cost credits. Avoid placing secrets or payment credentials in prompts, and use OpenClaw or pinned, reviewed setup commands instead of unpinned npx commands where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:262
Finding

Unpinned Third-Party Installer and Mutable Skill Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 262-268
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

bash
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup

Technical Analysis

The documented setup commands invoke the skills npm package through npx without specifying an exact package version. They also install Skill content from the mutable AgentPMT/agent-skills source without pinning an immutable commit, release, checksum, or cryptographic signature.

Consequently, the components executed or installed when a user follows these instructions may differ from those present when this Skill was audited. This creates a supply-chain trust boundary: compromise of the npm package, its publishing account, the upstream repository, or its distribution infrastructure could cause users to execute or install attacker-controlled content.

This access exceeds the minimum privileges needed by the reviewed package itself, which is documentation-only and merely describes remote trade-data queries. The setup process introduces a local package execution and Skill-installation capability that is not intrinsically necessary to parse the schema or understand the supported query parameters.

Attack Path

  1. An attacker compromises the npm package, its publisher credentials, the AgentPMT/agent-skills upstream source, or another component in the installation chain.
  2. The attacker publishes a modified installer or replaces the referenced Skill content with malicious instructions or executable setup behavior.
  3. A user follows the unpinned npx skills add ... command from SKILL.md.
  4. npx resolves the package available at execution time rather than a previously audited immut ...[truncated 944 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npm command to a specifically reviewed version, for example by using npx skills@<exact-version> rather than an unversioned package reference.
  2. Pin the AgentPMT Skill source to an immutable commit hash or cryptographically signed release instead of a mutable repository branch.
  3. Publish and verify cryptographic checksums or signatures for downloaded Skill content before installation.
  4. Use npm lockfiles and integrity metadata where the installation workflow supports them.
  5. Prefer a reviewed manual configuration procedure when only an MCP or REST endpoint must be configured, avoiding unnecessary local package execution.
  6. Run installation in a restricted environment with minimal filesystem, credential, network, and process permissions.
  7. Document the exact expected package version, source revision, downloaded files, and verification procedure so users can confirm that the installed content matches the audited release.
  8. Require explicit user confirmation before executing third-party installers or replacing existing Skills.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction states that the interface "Uses English country names only," which imposes a language constraint without user opt-in. This is a natural-language policy concern because it forces a specific language/locale behavior rather than offering alternatives or documenting a justified regional limitation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The listed search and activation keywords include broad phrases such as "query trade data" and especially "country or region," which can overlap with ordinary conversation and may cause unintended skill selection. The file does not provide negative examples or clear constraints distinguishing when these terms should or should not trigger this skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 331)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/trade-competitiveness-data
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 332)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/trade-competitiveness-data
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L022 states that country_or_region must be provided 'in English' and that Unicode names are not supported. This is a natural-language locale constraint that restricts user input to a specific language without opt-in or justification, which matches the policy-violation category.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.