T08 · Insecure Dependencies
- Location
SKILL.md:186- Finding
Unpinned External Dependency Retrieval and Execution Through npx
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it claims, but it sends email addresses to a hosted service and includes broad activation/update/install instructions that users should review before installing.
Install only if you are comfortable sending each checked email address to AgentPMT and spending verification credits. Prefer pinned or ClawHub-managed installation paths, avoid automatic reinstall/update behavior without review, and require explicit user consent before validating third-party or customer email addresses.
SKILL.md:186Unpinned External Dependency Retrieval and Execution Through npx
The top-level description is broad enough to match many normal signup, marketing, or anti-fraud workflows without clearly signaling third-party transmission. Ambiguous trigger scope increases the risk that an agent will select this skill automatically and send user email data externally when the user expected only local validation.
The skill explains remote DNS/MX and SMTP mailbox verification but does not clearly warn users that the submitted email address is sent to an external third-party service for processing. Since email addresses are personal data and the service also performs mailbox-level checks, the missing disclosure can lead to privacy violations, policy noncompliance, and user surprise.
The activation keywords include broad, everyday terms such as verify and email, which can cause the skill to trigger in contexts unrelated to explicit email-verification requests. Because this skill sends addresses to a remote third-party service and may consume paid credits, unintended invocation can leak personal data and trigger unauthorized external actions.
The skill includes npx skills add ... install commands without pinning an exact package or repository version. That creates a supply-chain risk because future upstream changes or a compromised package/repo could cause users to install unexpected code or a different skill definition than was reviewed.
This line references npx skills without a pinned version, so installation behavior depends on whatever is current upstream at execution time. In a skill ecosystem, that weakens reproducibility and can expose users to malicious or unreviewed updates via the package or referenced repository.
The unpinned npx skills command allows remote content resolution at runtime from a moving target. If the dependency source is altered or compromised, users following the skill instructions may fetch attacker-controlled code or instructions.
Because the install command is not version-pinned, the reviewed skill text does not guarantee the same artifact will be installed later. This is a classic supply-chain and reproducibility issue, especially for instructions encouraging command execution from remote package registries.
This install instruction again relies on an unpinned npx skills invocation, exposing users to upstream drift or package compromise. Repeated unpinned commands increase the chance that users will execute an unsafe installation path without realizing it.
The command references a remote package/repository without fixing the version, making the install path vulnerable to substitution by later upstream changes. This is dangerous because users are instructed to execute the command directly, which can transitively trust compromised dependencies.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/email-address-validation-single
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/email-address-validation-single
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The schema explicitly describes transmitting a user-supplied email address to a remote verification service for DNS/MX and SMTP mailbox checks, but it does not warn users that personal data will leave the local agent environment. This creates a privacy and consent risk because agents or developers may submit end-user email addresses to a third party without adequate disclosure, policy review, or legal basis.
No suspicious patterns detected.