Back to skill

Security audit

Global Energy Power Grid Data

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent AgentPMT energy-data skill, but it includes unpinned remote install/reinstall guidance that can change installed agent components.

Install only if you are comfortable using AgentPMT-hosted paid remote calls for energy-data queries. Prefer the OpenClaw install path or a pinned, reviewed version of any setup skill, and avoid running the documented unpinned `npx` commands in an environment with sensitive files, secrets, or elevated permissions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:270
Finding

Unpinned Third-Party Installer Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:270, 274, 279-280, 335-336
Vulnerability Type: Unpinned executable dependency and mutable supply-chain source
Risk Level: Medium

Vulnerable Code

markdown
- skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`
- skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`
bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup

The same unpinned installation commands are repeated in the AgentPMT reference section.

Technical Analysis

The Skill directs users or agents to invoke npx to obtain and execute third-party installer tooling and install content from AgentPMT/agent-skills. Neither the installer package nor the requested Skill source is pinned to an immutable version or commit. The instructions also provide no checksum, signature, lockfile, or other integrity-verification mechanism.

Consequently, the code executed when these commands are followed may differ from the content that existed when this Skill was audited. This creates a supply-chain trust boundary outside the reviewed project. The risk is heightened because one installed component configures AgentPMT account, MCP, and REST connectivity and may therefore participate in security-sensitive credential handling.

This audit did not establish that the external packages are currently malicious. The vulnerability is the unsafe reliance on mutable, remotely resolved executable dependencies without integrity controls.

Attack Path

  1. An attacker compromises the relevant package registry entry, upstream repository, maintainer account, release process, or transitive dependency.
  2. The attacker publishes or substitutes a malicious version while retaining the expected package or repository identity.
  3. A user or agent follows the commands documented in ` ...[truncated 1062 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npx package to a specific, audited version rather than relying on mutable resolution.
  2. Pin AgentPMT/agent-skills to an immutable commit or signed release tag.
  3. Publish and verify cryptographic checksums or signatures before executing or installing downloaded content.
  4. Document the exact trusted registry and repository source and disable unexpected fallback registries.
  5. Use a lockfile or equivalent integrity metadata for installer and transitive dependencies.
  6. Prefer a download-and-review workflow over directly executing remotely resolved content.
  7. Run installation in a restricted sandbox with no unnecessary secrets, filesystem access, or elevated permissions.
  8. Independently audit the account setup Skill because it operates near authentication and account-connectivity boundaries.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation keywords include broad phrases like general research and query terms that can cause the skill to trigger on loosely related prompts. In an agentic environment, overbroad routing can send user requests and context to a paid remote tool unnecessarily, increasing unintended data exposure and tool misuse risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 338)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/energy-access-production
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 339)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/energy-access-production
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Static analysis

No suspicious patterns detected.