Back to skill

Security audit

Email Address Validation Single

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it sends email addresses to a hosted service and includes broad activation/update/install instructions that users should review before installing.

Install only if you are comfortable sending each checked email address to AgentPMT and spending verification credits. Prefer pinned or ClawHub-managed installation paths, avoid automatic reinstall/update behavior without review, and require explicit user consent before validating third-party or customer email addresses.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:186
Finding

Unpinned External Dependency Retrieval and Execution Through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The top-level description is broad enough to match many normal signup, marketing, or anti-fraud workflows without clearly signaling third-party transmission. Ambiguous trigger scope increases the risk that an agent will select this skill automatically and send user email data externally when the user expected only local validation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explains remote DNS/MX and SMTP mailbox verification but does not clearly warn users that the submitted email address is sent to an external third-party service for processing. Since email addresses are personal data and the service also performs mailbox-level checks, the missing disclosure can lead to privacy violations, policy noncompliance, and user surprise.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation keywords include broad, everyday terms such as verify and email, which can cause the skill to trigger in contexts unrelated to explicit email-verification requests. Because this skill sends addresses to a remote third-party service and may consume paid credits, unintended invocation can leak personal data and trigger unauthorized external actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill includes npx skills add ... install commands without pinning an exact package or repository version. That creates a supply-chain risk because future upstream changes or a compromised package/repo could cause users to install unexpected code or a different skill definition than was reviewed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This line references npx skills without a pinned version, so installation behavior depends on whatever is current upstream at execution time. In a skill ecosystem, that weakens reproducibility and can expose users to malicious or unreviewed updates via the package or referenced repository.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The unpinned npx skills command allows remote content resolution at runtime from a moving target. If the dependency source is altered or compromised, users following the skill instructions may fetch attacker-controlled code or instructions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Because the install command is not version-pinned, the reviewed skill text does not guarantee the same artifact will be installed later. This is a classic supply-chain and reproducibility issue, especially for instructions encouraging command execution from remote package registries.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This install instruction again relies on an unpinned npx skills invocation, exposing users to upstream drift or package compromise. Repeated unpinned commands increase the chance that users will execute an unsafe installation path without realizing it.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The command references a remote package/repository without fixing the version, making the install path vulnerable to substitution by later upstream changes. This is dangerous because users are instructed to execute the command directly, which can transitively trust compromised dependencies.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 252)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/email-address-validation-single
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 253)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/email-address-validation-single
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema explicitly describes transmitting a user-supplied email address to a remote verification service for DNS/MX and SMTP mailbox checks, but it does not warn users that personal data will leave the local agent environment. This creates a privacy and consent risk because agents or developers may submit end-user email addresses to a third party without adequate disclosure, policy review, or legal basis.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.