Back to skill

Security audit

File Management

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent AgentPMT file-management integration, but it enables cloud upload, permanent deletion, and public sharing with incomplete safety guidance.

Review before installing. Use the skill only for files you are willing to store with AgentPMT, require explicit confirmation before delete or share actions, set short share password expiration and use limits, avoid placing secrets or wallet material in prompts or logs, and prefer pinned or verified install commands for related setup skills.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:246
Finding

Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 246-267
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

markdown
If those setup skills are not installed beside this product skill, use the downloads below.

Core AgentPMT setup skills:
- What AgentPMT is: ../what-is-agentpmt
  - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt
  - OpenClaw install: `openclaw skills install what-is-agentpmt`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup
  - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup
  - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`
- No-account AgentAddress/x402 setup: ../agentpmt-no-account-agentaddress-x402
  - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-no-account-agentaddress-x402
  - OpenClaw install: `openclaw skills install agentpmt-no-account-agentaddress-x402`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-no-account-agentaddress-x402`

skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
npx skills add AgentPMT/agent-skills --skill agentpmt-no-account-agentaddress-x402
text

### Technical Analysis

The Skill instructs users to invoke an unpinned npm-distributed CLI and install mutable Skill content from external sources. The commands do not identify a fixed CLI version, repository commit, release digest, checksum, or cryptographic signature. Consequently, the material installed at execution time may differ from the material that was reviewed during this audit.

The freshness 
...[truncated 1887 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the npm CLI to an explicitly reviewed version rather than invoking an unspecified latest release.
  • Pin each external Skill to an immutable commit hash or signed release identifier.
  • Publish SHA-256 or stronger checksums and verify them before installation.
  • Require signed releases and verify signatures against documented maintainer keys.
  • Use lockfiles or equivalent immutable dependency manifests where supported.
  • Download and inspect setup Skills before activation, particularly Skills that handle accounts, authentication, payments, or wallets.
  • Avoid automatic or time-based reinstallation without integrity verification and change review.
  • Run installation in a sandbox with minimal filesystem, credential, network, and wallet access.
  • Document the expected publisher identity, package name, version, repository, and verification procedure to reduce dependency-confusion and account-takeover risks.

T09 · Insecure Skill Coding Practices

Note
Location
schema.md:308
Finding

Public Share Passwords Default to Unlimited Lifetime and Use

Content
View full analysis

Vulnerability Details

File Location: schema.md, lines 308-320
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Low

Vulnerable Code

markdown
## `share`

Action slug: `share`

x402 action URL: `POST https://www.agentpmt.com/api/external/tools/file-management/actions/share/invoke`

Price: `5` credits

Create or refresh a password-protected public share link for an existing file.

Parameters:

| Parameter | Type | Required | Description |
|---|---|---|---|
| `file_id` | `string` | yes | File UUID returned from upload. |
| `password_max_minutes` | `integer` | no | Minutes until the auto-generated password expires (1-10). Leave empty for no expiration. |
| `password_max_uses` | `integer` | no | Maximum number of times the auto-generated password can be used (1-10). Leave empty for unlimited uses. |

Technical Analysis

The public sharing operation makes both password lifetime and use-count restrictions optional. Omitting password_max_minutes creates a password with no expiration, while omitting password_max_uses permits unlimited use. These defaults violate least-privilege and secure-by-default principles because the least restrictive access policy is applied without explicit user approval.

Password protection reduces opportunistic access but does not compensate for an indefinitely reusable credential. If the public URL and generated password are exposed through logs, chat history, browser history, copied messages, or an unintended recipient, the credential remains useful until the underlying file expires, is deleted, or the share is otherwise changed.

Attack Path

  1. An agent invokes share with only the required file_id, omitting both optional restrictions.
  2. The service creates a public share whose password has no configured expiration and no use limit.
  3. The share URL and password are disclosed to an unintended party through forwarding, logging, m ...[truncated 743 chars]
Remediation
View remediation

Remediation Suggestions

  • Require both password_max_minutes and password_max_uses for public sharing.
  • If optional fields must remain supported, apply restrictive server-side defaults, such as a short expiration and a single permitted use.
  • Require explicit user confirmation before generating or refreshing a public share.
  • Clearly display the effective expiration, use count, and public-access implications before completing the operation.
  • Provide an immediate share-revocation operation and document how agents should invoke it.
  • Avoid recording share passwords or signed URLs in prompts, logs, telemetry, or persistent memory.
  • Rotate the generated password whenever a share is refreshed.
  • Return only the minimum share information needed by the requesting workflow and redact credentials from diagnostic output.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents a permanent delete action but does not instruct the agent or user to require confirmation before performing destructive operations. In agentic contexts, omission of a confirmation pattern can cause accidental irreversible data loss from ambiguous prompts or mis-executed workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The public sharing feature is described without a clear privacy or exposure warning, which can lead agents or users to create externally accessible links for sensitive files without understanding the risk. Even with password protection and expiry controls, sharing expands the data exposure surface beyond the original budget scope.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill recommends executing npx skills add ... without pinning an exact package version or immutable source. That creates a supply-chain risk: if the upstream package or dependency tree is compromised or changes unexpectedly, an operator could install and trust malicious code or altered skill content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This line instructs use of npx skills without version pinning, allowing execution of whatever package version is current at install time. In a skill-install path, that exposes users to dependency confusion, malicious updates, or silent behavior drift affecting the trusted toolchain.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

An unpinned npx invocation permits retrieval and execution of mutable remote package content. Because this is setup guidance for connecting tool infrastructure, compromise of the fetched package could lead to workstation or credential compromise before the user even uses the product skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The install script includes npx skills with no version constraint, which is a classic software supply-chain weakness. Users following copy-paste instructions may execute a compromised or unexpected package version with broad local permissions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This repeated unpinned installer invocation compounds supply-chain exposure by normalizing execution of mutable remote packages. Even if the current package is benign, future package takeover or dependency compromise could turn these instructions into an initial access vector.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using npx skills without an exact version makes the installation path depend on the latest published package state. In the context of agent tooling and account setup, that could expose users to malicious code execution or credential theft if the package ecosystem is attacked.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The reference section repeats an unpinned npx skills install command, preserving the same supply-chain risk. Because these commands are presented as authoritative setup guidance, users are likely to execute them without additional verification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This line again exposes readers to execution of mutable package code through npx. Repetition across the document increases the chance that users copy the insecure pattern into automation or production provisioning workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Another floating npx skills invocation creates a preventable trust-on-first-use risk. In a file-management skill that may later handle sensitive data and credentials through adjacent setup skills, compromise of the installer path has substantial downstream impact.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- No-account AgentAddress/x402 setup: ../agentpmt-no-account-agentaddress-x402 (ClawHub: `agentpmt-no-account-agentaddress-x402`, page: https://clawhub.ai/agentpmt/agentpmt-no-account-agentaddress-x402; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-no-account-agentaddress-x402`)
- Marketplace product: https://www.agentpmt.com/marketplace/file-management
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 330)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- No-account AgentAddress/x402 setup: ../agentpmt-no-account-agentaddress-x402 (ClawHub: `agentpmt-no-account-agentaddress-x402`, page: https://clawhub.ai/agentpmt/agentpmt-no-account-agentaddress-x402; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-no-account-agentaddress-x402`)
- Marketplace product: https://www.agentpmt.com/marketplace/file-management
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema documents a permanently destructive delete action without any explicit confirmation, warning, or safer workflow guidance. In an agentic context, this increases the chance of accidental or over-broad deletion when an agent follows user instructions or ambiguous prompts without an extra confirmation step.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The share action creates or refreshes public share links, yet the documentation does not clearly warn that this can expose file contents outside the original trust boundary. In an agent environment, omission of a privacy warning can cause unintended public disclosure, especially if agents treat sharing as a routine convenience action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The large-upload action sends data to an external service and optionally enables public sharing, but the documentation does not make that trust-boundary crossing explicit. This can lead agents or users to upload sensitive material without understanding third-party handling or downstream exposure risk.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · schema.md (reported line 453)May include surrounding context.

md
|---|---|---|---|
| `content_length_bytes` | `integer` | yes | Exact file size in bytes. Must match the Content-Length header on PUT. File size must be over 10MB and up to 100MB. |
| `content_type` | `string` | no | MIME type of the file. Default: application/octet-stream. |
| `expiration_days` | `integer` | no | Days until file expires and is automatically deleted (1-7). Default: 7. |
| `filename` | `string` | no | Original filename including extension. If omitted, a filename is auto-generated. |
| `metadata` | `object` | no | Custom metadata as key-value pairs to attach to the file. |
| `password_max_minutes` | `integer` | no | Minutes until the auto-generated share password expires (1-10). Only relevant when shared is true. |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · schema.md (reported line 493)May include surrounding context.

md
|---|---|---|---|
| `content_length_bytes` | `integer` | yes | Exact file size in bytes. Must match the Content-Length header on PUT. File size must be over 10MB and up to 100MB. |
| `content_type` | `string` | no | MIME type of the file. Default: application/octet-stream. |
| `expiration_days` | `integer` | no | Days until file expires and is automatically deleted (1-7). Default: 7. |
| `filename` | `string` | no | Original filename including extension. If omitted, a filename is auto-generated. |
| `metadata` | `object` | no | Custom metadata as key-value pairs to attach to the file. |
| `password_max_minutes` | `integer` | no | Minutes until the auto-generated share password expires (1-10). Only relevant when shared is true. |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · schema.md (reported line 555)May include surrounding context.

md
|---|---|---|---|
| `content_length_bytes` | `integer` | yes | Exact file size in bytes. Must match the Content-Length header on PUT. File size must be over 10MB and up to 100MB. |
| `content_type` | `string` | no | MIME type of the file. Default: application/octet-stream. |
| `expiration_days` | `integer` | no | Days until file expires and is automatically deleted (1-7). Default: 7. |
| `filename` | `string` | no | Original filename including extension. If omitted, a filename is auto-generated. |
| `metadata` | `object` | no | Custom metadata as key-value pairs to attach to the file. |
| `password_max_minutes` | `integer` | no | Minutes until the auto-generated share password expires (1-10). Only relevant when shared is true. |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · schema.md (reported line 595)May include surrounding context.

md
|---|---|---|---|
| `content_length_bytes` | `integer` | yes | Exact file size in bytes. Must match the Content-Length header on PUT. File size must be over 10MB and up to 100MB. |
| `content_type` | `string` | no | MIME type of the file. Default: application/octet-stream. |
| `expiration_days` | `integer` | no | Days until file expires and is automatically deleted (1-7). Default: 7. |
| `filename` | `string` | no | Original filename including extension. If omitted, a filename is auto-generated. |
| `metadata` | `object` | no | Custom metadata as key-value pairs to attach to the file. |
| `password_max_minutes` | `integer` | no | Minutes until the auto-generated share password expires (1-10). Only relevant when shared is true. |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

As with large upload, the standard upload action omits notice that files are transmitted to an external service and may become publicly shareable. In a file-management skill, this omission materially raises the risk of accidental disclosure because uploading is a primary workflow and may involve sensitive files.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The upload_large documentation says content_type should be a MIME type, but the sample value is natural-language text (Draft marketing copy to check for banned phrases.) rather than a MIME type. This is an active contradiction in the inline documentation that could mislead implementers about the actual expected input.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The upload_standard documentation describes content_type as a MIME type, but the sample provides free-form document text instead of a MIME type. This directly conflicts with the parameter description and can cause misuse of the action.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.