Back to skill

Security audit

Data Format Validation

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed remote data-format validator, but it can send complete personal and financial values to AgentPMT with weak scoping and update guidance.

Install only if you are comfortable sending validation inputs to AgentPMT. Avoid using this skill with real payment cards, bank identifiers, customer records, secrets, private URLs, or sensitive JSON/Base64 unless your organization has approved AgentPMT processing and logging terms. Prefer pinned, reviewed installation paths for setup skills.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:137
Finding

Remote Transmission of Complete Financial and Personal Identifiers

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned and Mutable Third-Party Skill Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description includes broad discovery terms such as text, which is generic enough to cause accidental activation in unrelated workflows. Because this skill sends user-provided content to a remote AgentPMT-hosted service, overbroad triggering increases the chance of unintended external transmission of sensitive data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation keyword list again includes vague triggers, especially text, without constraints tying invocation to a clear validation request. In this context, broad matching is more dangerous because the skill is explicitly designed to forward arbitrary input strings to an external service, raising privacy and data-leak risk through misrouting.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The skill is built around transmitting supplied text values to external AgentPMT endpoints for validation, which creates a real data-exposure boundary. Although the file includes some cautions about not sending secrets, the supported use cases include highly sensitive fields such as credit card numbers and IBANs, so misuse could leak regulated or personal data to a third-party service.

Content

Scanner excerpt · SKILL.md (reported line 422)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/data-format-validation
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The documented REST invoke endpoint confirms that user inputs are sent off-box to a remote API. Given the skill's advertised validation of credit card numbers, phone numbers, emails, and IBANs, the context increases risk because agents may transmit sensitive personal or financial data under the guise of simple validation.

Content

Scanner excerpt · SKILL.md (reported line 423)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/data-format-validation
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly supports validation of highly sensitive inputs such as credit card numbers and IBANs, yet the schema provides no warning about handling personal or financial data. This increases the chance that agents or users will send raw secrets to a remote hosted tool unnecessarily, creating avoidable exposure through transmission, logging, retention, or downstream processing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description enumerates supported validation types as JSON, email, UUID, IPv4/6, MAC, credit card, IBAN, phone, hex color, ISBN, Base64, and regex patterns, but it does not mention URL validation. This schema adds a validate-url capability, which expands the documented behavior beyond the manifest's declared scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.