T08 · Insecure Dependencies
- Location
SKILL.md:371- Finding
Unpinned Remote Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent AgentPMT file parsing skill, but users should review it because it can send arbitrary documents to a remote service and recommends unpinned setup installs.
Install only if you are comfortable sending the selected files or file IDs to AgentPMT for remote processing. Avoid secrets, regulated data, or confidential documents unless your organization approves that use. Prefer the OpenClaw install path or pinned, reviewed setup commands instead of unpinned npx examples, and confirm before invoking this skill on sensitive uploads.
SKILL.md:371Unpinned Remote Skill Installation Creates a Supply-Chain Risk
The skill processes uploaded files through a remote AgentPMT-hosted service but does not clearly warn users that file contents may be transmitted to a third party for parsing. This omission can lead to inadvertent disclosure of sensitive documents, credentials, personal data, contracts, or regulated content because users may assume parsing happens locally.
The activation keywords are broad and generic for common file-processing tasks, with no exclusion conditions to prevent accidental invocation. In this skill's context, unintended matching is more dangerous because activation can route arbitrary uploaded files to a remote parsing service, causing privacy leaks, unnecessary cost, or processing of files that should stay local.
The skill instructs users to install supporting skills via npx skills without pinning an exact package version or immutable source. That creates a supply-chain risk: a later compromised or breaking upstream release could be fetched and executed during installation, especially because npx commonly downloads and runs packages on demand.
This line recommends npx skills without a pinned version for a related setup skill. Unpinned transient execution expands the trust boundary to whatever package version is current at install time, enabling supply-chain compromise or unexpected behavior if the package changes.
The skill references another unpinned npx skills installation path, which can cause users or agents to execute code from an uncontrolled latest release. In the context of agent skills and MCP tooling, this is particularly risky because setup utilities may receive credentials or alter runtime integrations.
This install example again uses npx skills without version pinning, introducing a repeatable supply-chain hazard. Attackers who compromise the upstream package or namespace could cause arbitrary code execution during installation or setup.
A second unpinned install command appears in the same script block, compounding the supply-chain exposure. Because these are setup steps for tool connectivity, a malicious package could tamper with credentials, endpoints, or agent configuration.
The reference section includes an unpinned npx skills command, again encouraging execution of mutable upstream code. Repetition across the document increases the chance that a user follows one of these unsafe installation paths.
This line repeats the same unpinned npx skills pattern for another setup dependency. In aggregate, these instructions normalize unsafe package execution and enlarge the attack surface for anyone onboarding the skill.
The skill clearly references remote AgentPMT MCP/REST endpoints used to transmit file content or file identifiers off-system for processing. External transmission is expected for the product, but it remains a real security concern because the tool handles arbitrary documents and the surrounding text does not pair the endpoint disclosure with strong user-facing consent or data-minimization safeguards.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/file-to-json-parsing
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
This line documents a REST invoke endpoint that will receive tool invocation parameters, potentially including base64-encoded file contents. While the endpoint itself is not malicious, the skill enables external transmission of potentially sensitive data and therefore needs stronger boundary warnings and tighter invocation safeguards.
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/file-to-json-parsing
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The manifest description says the skill parses files to JSON for CSV, HTML, JSON, and ICS calendars, with examples centered on those formats. This schema also exposes actions for ODS, PDF, RTF, plain text, XLS, XLSX, and a generic file-to-base64 conversion, which materially expands the advertised behavior beyond the stated manifest scope.
The skill is described as a file-to-JSON parsing utility, but this action converts arbitrary files to a base64 string rather than parsing them into structured JSON content. That is a separate file-transformation capability not clearly supported by the manifest’s stated purpose.
This markdown schema documents multiple actions that ingest user documents via file_id or input_base64, including PDFs, spreadsheets, calendars, and text files, but it provides no warning that uploaded file contents may contain sensitive or personal data. For markdown files, SQP-2 applies when the skill description omits warnings about behaviors that could affect user data or privacy.
No suspicious patterns detected.