Back to skill

Security audit

Global Debt Fiscal Explorer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for a paid AgentPMT fiscal-data tool, but its setup guidance relies on unpinned remote installers that could change after review.

Install only if you are comfortable using AgentPMT as an external paid service for fiscal data. Before running the `npx skills add` setup commands, verify the publisher and package version, prefer OpenClaw/ClawHub installation where possible, and avoid entering secrets, wallet material, or payment headers into prompts or logs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:247
Finding

Unpinned Remote Skill Installer Creates a Supply-Chain Execution Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 247-257
Vulnerability Type: Unpinned third-party installer and mutable remote dependencies
Risk Level: Medium

Vulnerable Code

markdown
- What AgentPMT is: ../what-is-agentpmt
  - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt
  - OpenClaw install: `openclaw skills install what-is-agentpmt`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup
  - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup
  - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`

skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
text

Equivalent unpinned commands are repeated at `SKILL.md:310-311`.

### Technical Analysis

The documented setup procedure invokes the `skills` package through `npx` without specifying a package version. It also identifies remote Skill content by a mutable repository and Skill name rather than an immutable commit, signed release, or verified artifact digest.

`npx` may download and execute the currently resolved package when a trusted local version is unavailable. Consequently, the effective installer code can change after this Skill has been reviewed. The subsequently installed setup Skills can also change independently of this package because their source revision is not pinned.

This is particularly relevant because the installed components are intended to configure AgentPMT account, MCP, and REST connectivity. Although the reviewed files contain no malicious executable code and explicitly advise against exposing secrets, the unpi
...[truncated 1963 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the skills npm package to a specifically audited version instead of relying on the latest registry resolution:
    bash
    npx --yes skills@<audited-version> add AgentPMT/agent-skills --skill what-is-agentpmt
    
  2. Pin AgentPMT/agent-skills to an immutable commit hash or signed release tag supported by the installer.
  3. Publish expected cryptographic checksums for downloaded artifacts and verify them before installation.
  4. Sign releases and require signature verification against a documented maintainer key.
  5. Use lockfiles and integrity metadata for all transitive dependencies involved in installation.
  6. Prefer a reviewed local copy of the required setup documentation where automatic remote installation is unnecessary.
  7. Document the exact files and permissions the installer requires, and advise users to run it without administrator privileges in an isolated environment.
  8. Add explicit guidance to inspect the resolved package version and remote revision before approving execution.
  9. Periodically review and update pinned versions through a controlled release process rather than silently accepting mutable upstream content.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation keywords include broad natural-language phrases like ordinary research tasks, which increases the chance this remote skill is invoked in contexts where a user only wanted general analysis. That can cause unintended external calls, unnecessary payment-triggering actions, or disclosure of user-supplied country/research context to the third-party service.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs users to install supporting skills via npx skills ... without pinning an exact package version or immutable source. That creates a supply-chain risk: future package updates or a compromised upstream release could silently change what gets installed and executed in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This line again references npx skills with no version pinning, so the installed code is whatever the registry serves at execution time. In a skill ecosystem, that can let an upstream compromise or breaking update affect downstream users without any change to this skill file.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The unpinned npx skills install command exposes users to dependency drift and registry compromise. Because it is presented as setup guidance, users may run it verbatim and execute unintended code from a later package version.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This is another floating npx skills command with the same supply-chain risk profile. Even though it installs a related setup skill rather than this product directly, compromise of that dependency could still lead to credential theft or malicious configuration.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The reference to npx skills add ... remains unpinned near the security/reference section, which can lend it extra authority and increase the chance users trust and execute it. Unpinned package execution is a recognized software supply-chain weakness.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This line repeats the same unpinned installation pattern for another prerequisite skill. If the registry package or transitive dependencies are compromised, users could execute attacker-controlled code during setup.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 313)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/debt-fiscal-management
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 314)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/debt-fiscal-management
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Static analysis

No suspicious patterns detected.