Back to skill

Security audit

Create 3d Model From Image

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed remote 3D-modeling integration, with the main caution that setup examples include unpinned install commands and user inputs are sent to AgentPMT.

Install from ClawHub/OpenClaw or a pinned, reviewed source when possible, especially because the skill's own freshness note says to reinstall after seven days and this copy is older than that. Treat AgentPMT inputs as data shared with a remote service, do not include secrets or private wallet material in prompts/logs, and confirm credit costs before creating or refining models.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:227
Finding

Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 227–228
Vulnerability Type: Unpinned third-party dependencies from mutable sources
Risk Level: Medium

Vulnerable Code

bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup

Technical Analysis

The documented setup procedure invokes the skills npm package through npx without pinning a verified package version. It also installs Skill content from the mutable AgentPMT/agent-skills repository without specifying an immutable commit hash, signed release, or integrity checksum.

Consequently, the content executed or installed when a user follows these instructions may differ from the content that existed when this Skill was audited. The installation also expands the trusted instruction and dependency surface beyond the two files included in this project.

Account setup may legitimately require an additional component, but retrieving mutable third-party content through an unpinned installer is not the minimum-risk method of providing that functionality. No evidence establishes that the current upstream package or repository is malicious; the vulnerability is the absence of controls preventing a future or compromised release from being trusted automatically.

Attack Path

  1. An agent or user follows the setup instructions in SKILL.md.
  2. npx resolves the current available version of the skills package rather than a version reviewed with this project.
  3. The installer retrieves the current contents of the mutable AgentPMT/agent-skills repository.
  4. An attacker who has compromised the npm package, repository, maintainer account, or distribution channel supplies modified installer or Skill content.
  5. The unverified content is installed and subsequently interpreted or executed as trusted Agent instructions.
  6. Depending on the installer an ...[truncated 1026 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npx package to a specific, reviewed version rather than resolving the latest release dynamically.
  2. Pin AgentPMT/agent-skills to an immutable commit hash or cryptographically signed release.
  3. Publish expected checksums or signatures and verify them before installation.
  4. Avoid automatic installation; require explicit user confirmation that identifies the source, version, requested permissions, and security implications.
  5. Prefer bundling the minimum audited setup instructions locally when feasible.
  6. Review installed setup Skills independently, especially any component that handles account credentials, MCP configuration, or REST authentication.
  7. Run installation with the least-privileged account available and prevent installers from accessing unrelated secrets or sensitive directories.
  8. Maintain a dependency allowlist and periodically reassess pinned versions for known vulnerabilities.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 300)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/create-3d-model-from-image
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 301)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/create-3d-model-from-image
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Static analysis

No suspicious patterns detected.