T09 · Insecure Skill Coding Practices
- Location
SKILL.md:149- Finding
Unnecessary Remote Disclosure of Caller-Provided Content
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 149, 238, 271, 408-438, and 454-455
Vulnerability Type: Sensitive-data transmission to an external service
Risk Level: MediumVulnerable Code Snippets
markdown - `input` (string) — CSV content as a stringmarkdown - `input` (string) — The content to hashmarkdown - All operations are stateless text transformations. This tool does not read from or write to the filesystem.json { "method": "tools/call", "params": { "name": "File-Utilities-and-Editing", "arguments": { "action": "file-base64-decode", "input": "example input" } } }json { "name": "file-utilities-and-editing", "parameters": { "action": "file-base64-decode", "input": "example input" } }markdown - AgentPMT main MCP server: https://api.agentpmt.com/mcp/ - AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchaseTechnical Analysis
The Skill instructs the agent to submit raw caller-provided inputs to AgentPMT-hosted MCP or REST endpoints. Depending on the selected action, transmitted data can include:
- CSV datasets
- Complete JSON documents
- Plaintext to be encoded or hashed
- Base64 content to be decoded
- Filenames and local path components
- Other document-derived text
These operations are deterministic text transformations that can be implemented locally without filesystem access or network privileges. Remote transmission therefore exceeds the minimum technical privileges necessary for the declared functionality.
Paths can disclose usernames, project names, directory structures, or internal resource names. CSV, JSON, Base64, and hashing inputs can contain personal data, credentials, business records, source material, or other confidential information. Once transmitted, that content crosses the local trust boundary a ...[truncated 1657 chars]
- Remediation
View remediation
Remediation Suggestions
- Implement MIME lookup, path handling, Base64 conversion, JSON formatting, CSV rendering, size formatting, and hashing locally by default.
- Require explicit user confirmation before transmitting any caller-provided content to AgentPMT.
- Clearly disclose the destination, fields transmitted, processing purpose, retention policy, and applicable privacy controls before invocation.
- Add automated detection and rejection for API keys, passwords, private keys, mnemonics, authentication headers, and other credential patterns.
- Minimize submitted data. For example, send only a filename extension for MIME lookup instead of a complete path.
- Redact personal data and confidential fields from JSON or CSV inputs before remote processing.
- Enforce TLS certificate validation and narrowly scope authentication credentials to the required product and actions.
- Document that Base64 is encoding rather than encryption and must not be used to protect sensitive information.
- Establish and document server-side logging, access-control, deletion, and retention guarantees.
