T09 · Insecure Skill Coding Practices
- Location
SKILL.md:137- Finding
Remote Transmission of Complete Financial and Personal Identifiers
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed remote data-format validator, but it can send complete personal and financial values to AgentPMT with weak scoping and update guidance.
Install only if you are comfortable sending validation inputs to AgentPMT. Avoid using this skill with real payment cards, bank identifiers, customer records, secrets, private URLs, or sensitive JSON/Base64 unless your organization has approved AgentPMT processing and logging terms. Prefer pinned, reviewed installation paths for setup skills.
SKILL.md:137Remote Transmission of Complete Financial and Personal Identifiers
SKILL.md:11Unpinned and Mutable Third-Party Skill Installation
The description includes broad discovery terms such as text, which is generic enough to cause accidental activation in unrelated workflows. Because this skill sends user-provided content to a remote AgentPMT-hosted service, overbroad triggering increases the chance of unintended external transmission of sensitive data.
The activation keyword list again includes vague triggers, especially text, without constraints tying invocation to a clear validation request. In this context, broad matching is more dangerous because the skill is explicitly designed to forward arbitrary input strings to an external service, raising privacy and data-leak risk through misrouting.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill is built around transmitting supplied text values to external AgentPMT endpoints for validation, which creates a real data-exposure boundary. Although the file includes some cautions about not sending secrets, the supported use cases include highly sensitive fields such as credit card numbers and IBANs, so misuse could leak regulated or personal data to a third-party service.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/data-format-validation
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The documented REST invoke endpoint confirms that user inputs are sent off-box to a remote API. Given the skill's advertised validation of credit card numbers, phone numbers, emails, and IBANs, the context increases risk because agents may transmit sensitive personal or financial data under the guise of simple validation.
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/data-format-validation
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The skill explicitly supports validation of highly sensitive inputs such as credit card numbers and IBANs, yet the schema provides no warning about handling personal or financial data. This increases the chance that agents or users will send raw secrets to a remote hosted tool unnecessarily, creating avoidable exposure through transmission, logging, retention, or downstream processing.
The manifest description enumerates supported validation types as JSON, email, UUID, IPv4/6, MAC, credit card, IBAN, phone, hex color, ISBN, Base64, and regex patterns, but it does not mention URL validation. This schema adds a validate-url capability, which expands the documented behavior beyond the manifest's declared scope.
No suspicious patterns detected.