Back to skill

Security audit

Financial Loan Amortization Calculator

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate hosted loan calculator, but it sends sensitive financial inputs to AgentPMT and can upload schedules to cloud storage without enough consent and retention detail.

Install only if you are comfortable sending loan, income, debt, refinance, and affordability details to AgentPMT. Avoid adding identifiers such as names, addresses, account numbers, or government IDs. Use schedule upload only when you need a downloadable file, treat signed URLs as sensitive, choose the shortest expiration, and prefer pinned or ClawHub-managed install paths over unpinned npx commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:513
Finding

Unpinned Third-Party Installation Commands Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 513-529
Vulnerability Type: Unpinned executable dependency and mutable Skill source
Risk Level: Medium

Evidence

markdown
If those setup skills are not installed beside this product skill, use the downloads below.

Core AgentPMT setup skills:
- What AgentPMT is: ../what-is-agentpmt
  - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt
  - OpenClaw install: `openclaw skills install what-is-agentpmt`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup
  - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup
  - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`

skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
text

### Technical Analysis

The installation instructions invoke an npm-delivered CLI through `npx` without specifying a reviewed version. They also install Skill content from a mutable repository reference without pinning an immutable commit or signed release.

Consequently, the installed code or instructions may differ from the content reviewed during this audit. Compromise of the npm package, publisher account, upstream repository, or distribution channel could cause future installations to retrieve malicious content. The separate freshness instruction encouraging reinstallation increases exposure to mutable upstream changes.

No evidence shows that the currently documented AgentPMT packages are malicious. The vulnerability is the absence of supply-chain integrity controls.

### Attack Path

1. An attacker compromises the
...[truncated 1076 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npm CLI to a reviewed version, for example by using an exact version rather than an implicit latest release.
  2. Pin Skill sources to immutable commit hashes or cryptographically signed release artifacts.
  3. Publish expected SHA-256 checksums and require verification before installation.
  4. Disable or review npm lifecycle scripts where possible.
  5. Avoid automatically encouraging reinstallation solely based on elapsed time; instead, identify a specific signed release and its security status.
  6. Execute installation in a restricted environment without unnecessary credentials, filesystem access, or administrative privileges.
  7. Document the exact code and instructions that each setup dependency installs.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:257
Finding

Sensitive Financial Information Is Sent to a Third-Party Service Without an Explicit Consent Gate

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 257-285; remote invocation is documented at lines 537-575 and 593-594
Vulnerability Type: External transmission of sensitive financial data without sufficient privacy controls
Risk Level: Medium

Evidence

markdown
##### affordability_analysis
Estimate affordable monthly payment, maximum loan principal, and maximum home price based on income and debts.

**Required Parameters:**
- `action` (string): `"affordability_analysis"`
- `annual_income` (number, >0): Gross annual income
- `annual_rate` (number, 0-100): Expected mortgage rate in percent
- `years` (number, >0): Loan term in years

**Optional Parameters:**
- `monthly_debts` (number, default: 0): Recurring monthly debt obligations
- `monthly_expenses` (number, default: 0): Additional recurring monthly expenses
- `property_tax_monthly` (number, default: 0)
- `insurance_monthly` (number, default: 0)
- `hoa_monthly` (number, default: 0)
- `down_payment` (number, default: 0): Down payment amount

**Example:**
```json
{
  "action": "affordability_analysis",
  "annual_income": 145000,
  "monthly_debts": 850,
  "annual_rate": 6.2,
  "years": 30,
  "down_payment": 60000
}
text

The external destinations are identified later in the file:

```markdown
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Technical Analysis

Affordability and refinancing operations require the Agent to transmit financial information—including annual income, debts, expenses, loan balances, payment amounts, closing costs, and down payments—to an AgentPMT-hosted MCP or REST service.

The remote processing behavior is declared and the values are relevant to the requested calculations, so the observed behavior is not covert exfiltration. Nevertheless, the Skill does not require explicit user co ...[truncated 1611 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit, informed user confirmation before sending financial information to AgentPMT.
  2. State the destination hostname and categories of transmitted data in the confirmation prompt.
  3. Document request retention, logging, deletion, encryption, subprocessors, and secondary-use policies.
  4. Send only fields required for the selected calculation and omit optional values unless needed.
  5. Instruct users and Agents not to include names, addresses, account numbers, government identifiers, or free-text notes.
  6. Provide a local calculation option for operations that do not require hosted storage or proprietary data.
  7. Ensure transport uses validated TLS and that authentication material remains outside prompts and ordinary logs.
  8. Add contractual and technical controls preventing submitted financial data from being used for advertising, profiling, or model training without separate consent.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:386
Finding

Recommended Workflow Enables Cloud Storage of Detailed Loan Schedules Without Separate User Confirmation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 386-402; upload parameters are defined at lines 185-211
Vulnerability Type: Optional sensitive-file upload promoted without an explicit consent or retention boundary
Risk Level: Medium

Evidence

markdown
#### Workflows

1. **Home Purchase Planning** - Use `affordability_analysis` to determine budget, then `calculate_payment` to see exact payments, then `amortization_schedule` with `store_schedule_file: true` for a downloadable payment plan.
markdown
- Set `return_schedule: false` to get only the summary without period-by-period rows.
- CSV file uploads via `store_schedule_file` expire in 1-7 days (configurable via `expiration_days`).

The upload option and returned access URL are defined as follows:

markdown
- `store_schedule_file` (boolean, default: false): Upload schedule as CSV to cloud storage
- `expiration_days` (integer, default: 7, range: 1-7): Cloud file expiration in days

When `store_schedule_file` is true: `schedule_file` with `file_id`,
`signed_url`, `expiration_date`, `size_bytes`.

Technical Analysis

Although store_schedule_file safely defaults to false, the recommended home-purchase workflow explicitly changes it to true. This causes a detailed amortization schedule to be uploaded to cloud storage rather than merely returned in the current tool response.

Such a schedule may expose principal, payment dates, payment amounts, interest charges, extra payments, remaining balances, and cumulative amounts. The Skill does not identify the storage provider, define access-control guarantees, require separate confirmation, or explain whether expiration of the signed URL also deletes the stored object.

A signed URL is effectively a bearer credential: anyone who obtains it may be able to access the file until it expires. Returning that URL through an Agent also creates opportunities for it to appear in con ...[truncated 1217 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not enable store_schedule_file merely because a workflow requests a downloadable plan.
  2. Require separate user confirmation immediately before cloud upload.
  3. Clearly disclose the storage provider, region, retention duration, deletion behavior, and access-control model.
  4. Use the shortest practical signed-URL expiration and make URLs single-use where supported.
  5. Ensure stored objects are deleted when their access period expires rather than only invalidating the URL.
  6. Prevent signed URLs from appearing in telemetry, application logs, debugging traces, and persistent Agent memory.
  7. Provide a local CSV-generation or direct-response option that avoids cloud storage.
  8. Minimize exported columns and avoid adding exact dates unless the user explicitly needs them.
  9. Allow users to revoke access and delete uploaded schedules before their scheduled expiration.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly supports uploading amortization schedules to cloud storage via store_schedule_file, but it does not present a prominent warning that sensitive financial data may be transmitted off-system and exposed through signed URLs. In a finance context, loan balances, payment schedules, and related dates are sensitive personal financial information, so silent or underexplained export behavior increases privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill is designed to send user-supplied financial inputs to external AgentPMT endpoints, which is an intentional external transmission of potentially sensitive financial data. In this context that behavior is expected, but it still creates real privacy and data-exposure risk if users are not clearly informed what data leaves the local environment and under what protections.

Content

Scanner excerpt · SKILL.md (reported line 593)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/financial-loan-calculator
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This line references the REST purchase/invocation endpoint, confirming that requests are sent to an external service. Because the tool handles loan, income, debt, and affordability information, remote transmission materially increases confidentiality risk even if the service is legitimate and the behavior is part of the product design.

Content

Scanner excerpt · SKILL.md (reported line 594)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/financial-loan-calculator
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The amortization_schedule action can upload generated CSV schedules to cloud storage and return file metadata, but the schema provides no user-facing warning that financial data may be exported off-platform or persisted remotely. Because loan schedules can contain sensitive financial details, this creates a privacy and data-handling risk if users or downstream agents enable file export without understanding retention, sharing, or exposure implications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.