T09 · Insecure Skill Coding Practices
- Location
SKILL.md:406- Finding
Arbitrary User Content Is Transmitted to a Third-Party Service
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to be an advertised remote text encoder, but it needs review because it can send arbitrary user text to AgentPMT and lets mutable remote/setup content influence behavior.
Install only if you are comfortable sending the text you encode or decode to AgentPMT and spending the listed credits. Do not use it for secrets, credentials, private keys, proprietary files, regulated data, or sensitive payloads unless your organization explicitly approves the AgentPMT service. Prefer local encoding tools for routine transformations, and audit or pin the referenced setup skills before using the npx installation path.
SKILL.md:406Arbitrary User Content Is Transmitted to a Third-Party Service
SKILL.md:388Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk
SKILL.md:319Remote Instructions Are Allowed to Override Audited Local Guidance
The activation keywords include very broad terms such as text, which can cause this remote-tool skill to be selected in many unrelated contexts. Because the tool sends user-provided content to an external AgentPMT service, overbroad triggering increases the chance of unnecessary data exposure, unintended paid calls, or workflow confusion in contexts where a local transformation would have been safer.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill explicitly routes input to an external MCP/API endpoint at api.agentpmt.com, meaning any text provided to this encoder may leave the local environment. In context, this tool handles arbitrary user text and even mentions file content and payload encoding use cases, so accidental transmission of secrets, source code, credentials, or regulated data is a realistic confidentiality risk.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/data-format-encoder
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
This REST invoke endpoint confirms that tool usage results in external transmission to a third-party service. For an encoding utility, many operations could be performed locally, so the remote design materially increases privacy and compliance risk if agents use it on confidential text without clear consent or data classification checks.
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/data-format-encoder
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Price: `5` credits
Convert a hexadecimal string back to plain text. Spaces, colons, and hyphens between hex bytes are automatically removed.
Parameters:
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Price: `5` credits
Convert a hexadecimal string back to plain text. Spaces, colons, and hyphens between hex bytes are automatically removed.
Parameters:
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Price: `5` credits
Convert a hexadecimal string back to plain text. Spaces, colons, and hyphens between hex bytes are automatically removed.
Parameters:
No suspicious patterns detected.