Back to skill

Security audit

File Utilities And Editing

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed remote AgentPMT file-utility skill with no bundled code or persistence, but users should avoid sending sensitive content and be cautious with its unpinned setup examples.

Installers should prefer the OpenClaw route or pin and review any npx-based setup before running it. When using the skill, treat AgentPMT as an external processor: do not send secrets, private keys, credentials, confidential documents, or unnecessary personal/business data in the input fields.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:149
Finding

Unnecessary Remote Disclosure of Caller-Provided Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 149, 238, 271, 408-438, and 454-455
Vulnerability Type: Sensitive-data transmission to an external service
Risk Level: Medium

Vulnerable Code Snippets

markdown
- `input` (string) — CSV content as a string
markdown
- `input` (string) — The content to hash
markdown
- All operations are stateless text transformations. This tool does not read from or write to the filesystem.
json
{
  "method": "tools/call",
  "params": {
    "name": "File-Utilities-and-Editing",
    "arguments": {
      "action": "file-base64-decode",
      "input": "example input"
    }
  }
}
json
{
  "name": "file-utilities-and-editing",
  "parameters": {
    "action": "file-base64-decode",
    "input": "example input"
  }
}
markdown
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Technical Analysis

The Skill instructs the agent to submit raw caller-provided inputs to AgentPMT-hosted MCP or REST endpoints. Depending on the selected action, transmitted data can include:

  • CSV datasets
  • Complete JSON documents
  • Plaintext to be encoded or hashed
  • Base64 content to be decoded
  • Filenames and local path components
  • Other document-derived text

These operations are deterministic text transformations that can be implemented locally without filesystem access or network privileges. Remote transmission therefore exceeds the minimum technical privileges necessary for the declared functionality.

Paths can disclose usernames, project names, directory structures, or internal resource names. CSV, JSON, Base64, and hashing inputs can contain personal data, credentials, business records, source material, or other confidential information. Once transmitted, that content crosses the local trust boundary a ...[truncated 1657 chars]

Remediation
View remediation

Remediation Suggestions

  1. Implement MIME lookup, path handling, Base64 conversion, JSON formatting, CSV rendering, size formatting, and hashing locally by default.
  2. Require explicit user confirmation before transmitting any caller-provided content to AgentPMT.
  3. Clearly disclose the destination, fields transmitted, processing purpose, retention policy, and applicable privacy controls before invocation.
  4. Add automated detection and rejection for API keys, passwords, private keys, mnemonics, authentication headers, and other credential patterns.
  5. Minimize submitted data. For example, send only a filename extension for MIME lookup instead of a complete path.
  6. Redact personal data and confidential fields from JSON or CSV inputs before remote processing.
  7. Enforce TLS certificate validation and narrowly scope authentication credentials to the required product and actions.
  8. Document that Base64 is encoding rather than encryption and must not be used to protect sensitive information.
  9. Establish and document server-side logging, access-control, deletion, and retention guarantees.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:394
Finding

Unpinned Third-Party Installer Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 394, 398, 403-404, and 451-452
Vulnerability Type: Mutable dependency and installer execution
Risk Level: Medium

Vulnerable Code Snippet

markdown
Core AgentPMT setup skills:
- What AgentPMT is: ../what-is-agentpmt
  - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt
  - OpenClaw install: `openclaw skills install what-is-agentpmt`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup
  - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup
  - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`

skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
text

### Technical Analysis

The setup instructions recommend invoking `npx` to obtain and execute a third-party package, which then installs Skills from `AgentPMT/agent-skills`. Neither the npm package version nor the Skill repository revision is pinned to an immutable, audited release or commit. No integrity hash or signature-verification step is specified.

Consequently, the effective installer and installed content can change after this Skill has been reviewed. If the npm package, package maintainer account, source repository, release pipeline, or dependency chain is compromised, following the documented command could execute altered code under the invoking user's account.

This is a supply-chain weakness rather than evidence that the referenced package is currently malicious. The audit found no embedded scripts in this project and no proof of an existing compromise.

### Attack Path

1. An
...[truncated 1244 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npx package to a specific audited version rather than allowing resolution of the current release.
  2. Pin the Skill repository to an immutable commit hash or signed release tag.
  3. Publish and verify cryptographic integrity hashes for downloaded packages and Skill files.
  4. Use lockfiles with integrity metadata for all installer dependencies.
  5. Require signed releases and verify signatures before installation.
  6. Disable or carefully review npm lifecycle scripts where feasible.
  7. Download packages without execution, inspect their contents, and execute only after verification.
  8. Run installation in a sandbox or container with minimal filesystem, credential, and network access.
  9. Avoid running setup commands as root or an administrator.
  10. Document the exact expected package version, repository revision, checksums, and verification procedure.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill instructs users to run npx skills ... without pinning an exact package version or integrity hash. That creates a supply-chain risk: a later compromised or malicious package version could be fetched and executed at install time, which is especially relevant because these commands are presented as setup steps for integrating remote tooling.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The unpinned npx skills invocation allows resolution of whatever package version is current at execution time. In a skill-installation context, that can expose users to remote code execution through dependency or publisher compromise, even if the skill itself is otherwise benign.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This install instruction references npx skills without version pinning, so execution depends on mutable upstream state. Because npx may download and execute packages immediately, a compromised upstream release could lead to unintended code execution on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The command uses an unpinned package reference for runtime installation. In practice, this means the security posture of the skill depends on the current state of the package registry and transitive dependencies, which is a real supply-chain vulnerability for consumers following the documented setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skills.sh install example relies on npx skills without constraining the package version. That exposes users to a mutable external package source during installation, increasing the risk of supply-chain compromise and arbitrary code execution if the package or dependency chain is hijacked.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This second skills.sh example repeats the same unpinned npx skills pattern, preserving the same supply-chain risk. Since the content is user-facing setup guidance, the danger is amplified by likely copy-paste execution of the command.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 454)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/file-utilities-and-editing
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 455)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/file-utilities-and-editing
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Static analysis

No suspicious patterns detected.