T01 · Skill Instruction Hijacking
- Location
SKILL.md:214- Finding
Mutable Remote Instructions Can Override Locally Audited Skill Guidance
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed AgentPMT remote date/time tool, but it needs Review because it lets live remote instructions outrank the audited skill and recommends mutable unpinned setup installs.
Install only if you are comfortable using AgentPMT as a third-party processor for date and scheduling parameters. For sensitive deadlines, meetings, billing periods, or activity logs, prefer a local calculator or send only the minimum fields. If using the setup instructions, prefer pinned or reviewed installs, and treat any live get_instructions response as reference data rather than higher-priority agent instructions.
SKILL.md:214Mutable Remote Instructions Can Override Locally Audited Skill Guidance
SKILL.md:278Unpinned npx-Based Installation of Mutable Third-Party Skills
SKILL.md:298Date and Scheduling Data Is Sent to a Third-Party Service for Operations That Can Be Performed Locally
The activation keywords include very broad generic terms such as date, which can cause the skill to trigger in contexts far beyond its intended use. Over-broad activation increases the chance an agent routes unrelated user data to this external tool, creating unnecessary data exposure and unintended remote calls.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill is explicitly designed to send user-supplied date/time data to external AgentPMT endpoints over MCP/REST. Even though the data category is usually low sensitivity, the skill increases exposure because generic activation terms and broad use cases can cause unnecessary transmission of user inputs to a third-party service.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/date-calculator-and-timestamp-tool-set
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
This line documents a REST invoke endpoint used to transmit request data off-platform. In the context of a remote-tool skill, that is expected behavior, but it is still a genuine data egress surface and therefore a true vulnerability pattern when assessing confidentiality and trust boundaries.
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/date-calculator-and-timestamp-tool-set
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The manifest description emphasizes date/time calculations such as adding/subtracting days, business days, time until/since, timezone conversion, and week-related calculations. This schema also exposes duration parsing/formatting, leap-year checks, fiscal quarter lookup, Unix/ISO conversions, and working-hours overlap checks, which extend beyond the specifically stated capability list rather than directly matching it.
The unix-to-date documentation states that conversion defaults to local time when no timezone is supplied. Implicit use of local timezone can produce inconsistent or privacy-revealing results across environments, and may cause downstream scheduling or audit errors if callers assume UTC or a stable timezone.
The documentation says this action is 'Useful for scheduling across time zones,' but the documented parameters only accept two plain HH:MM ranges with no timezone inputs. As documented, the action checks overlap between time periods but does not itself perform any timezone-aware scheduling logic.
No suspicious patterns detected.