Back to skill

Security audit

File To Json Parsing

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent AgentPMT file parsing skill, but users should review it because it can send arbitrary documents to a remote service and recommends unpinned setup installs.

Install only if you are comfortable sending the selected files or file IDs to AgentPMT for remote processing. Avoid secrets, regulated data, or confidential documents unless your organization approves that use. Prefer the OpenClaw install path or pinned, reviewed setup commands instead of unpinned npx examples, and confirm before invoking this skill on sensitive uploads.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:371
Finding

Unpinned Remote Skill Installation Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill processes uploaded files through a remote AgentPMT-hosted service but does not clearly warn users that file contents may be transmitted to a third party for parsing. This omission can lead to inadvertent disclosure of sensitive documents, credentials, personal data, contracts, or regulated content because users may assume parsing happens locally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation keywords are broad and generic for common file-processing tasks, with no exclusion conditions to prevent accidental invocation. In this skill's context, unintended matching is more dangerous because activation can route arbitrary uploaded files to a remote parsing service, causing privacy leaks, unnecessary cost, or processing of files that should stay local.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs users to install supporting skills via npx skills without pinning an exact package version or immutable source. That creates a supply-chain risk: a later compromised or breaking upstream release could be fetched and executed during installation, especially because npx commonly downloads and runs packages on demand.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This line recommends npx skills without a pinned version for a related setup skill. Unpinned transient execution expands the trust boundary to whatever package version is current at install time, enabling supply-chain compromise or unexpected behavior if the package changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill references another unpinned npx skills installation path, which can cause users or agents to execute code from an uncontrolled latest release. In the context of agent skills and MCP tooling, this is particularly risky because setup utilities may receive credentials or alter runtime integrations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This install example again uses npx skills without version pinning, introducing a repeatable supply-chain hazard. Attackers who compromise the upstream package or namespace could cause arbitrary code execution during installation or setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

A second unpinned install command appears in the same script block, compounding the supply-chain exposure. Because these are setup steps for tool connectivity, a malicious package could tamper with credentials, endpoints, or agent configuration.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The reference section includes an unpinned npx skills command, again encouraging execution of mutable upstream code. Repetition across the document increases the chance that a user follows one of these unsafe installation paths.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This line repeats the same unpinned npx skills pattern for another setup dependency. In aggregate, these instructions normalize unsafe package execution and enlarge the attack surface for anyone onboarding the skill.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill clearly references remote AgentPMT MCP/REST endpoints used to transmit file content or file identifiers off-system for processing. External transmission is expected for the product, but it remains a real security concern because the tool handles arbitrary documents and the surrounding text does not pair the endpoint disclosure with strong user-facing consent or data-minimization safeguards.

Content

Scanner excerpt · SKILL.md (reported line 430)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/file-to-json-parsing
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This line documents a REST invoke endpoint that will receive tool invocation parameters, potentially including base64-encoded file contents. While the endpoint itself is not malicious, the skill enables external transmission of potentially sensitive data and therefore needs stronger boundary warnings and tighter invocation safeguards.

Content

Scanner excerpt · SKILL.md (reported line 431)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/file-to-json-parsing
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description says the skill parses files to JSON for CSV, HTML, JSON, and ICS calendars, with examples centered on those formats. This schema also exposes actions for ODS, PDF, RTF, plain text, XLS, XLSX, and a generic file-to-base64 conversion, which materially expands the advertised behavior beyond the stated manifest scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is described as a file-to-JSON parsing utility, but this action converts arbitrary files to a base64 string rather than parsing them into structured JSON content. That is a separate file-transformation capability not clearly supported by the manifest’s stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown schema documents multiple actions that ingest user documents via file_id or input_base64, including PDFs, spreadsheets, calendars, and text files, but it provides no warning that uploaded file contents may contain sensitive or personal data. For markdown files, SQP-2 applies when the skill description omits warnings about behaviors that could affect user data or privacy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.