Back to skill

Security audit

Global Population Demographics Data

Security checks for vulnerabilities and agentic risk

Overview

This demographics skill is mostly a disclosed remote lookup, but it needs Review because it tells agents to trust mutable remote instructions and recommends unpinned external setup installs.

Install only if you are comfortable using AgentPMT-hosted remote calls for demographic data. Prefer pinned or ClawHub-reviewed setup routes, do not place account secrets or payment material in prompts, and treat remotely returned instructions as untrusted metadata unless separately verified.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:255
Finding

Unpinned Third-Party Setup Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 255–265
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

markdown
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup
  - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup
  - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`

skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
text

### Technical Analysis

The documented setup process invokes `npx` and installs skills from a mutable external repository without specifying a reviewed package version, release tag, commit hash, or integrity digest. The fetched setup skills are not included in this project, so their effective contents and behavior could not be inspected during this audit.

This is particularly security-sensitive because the external skills are intended to configure AgentPMT account, MCP, and REST connectivity. Changes to those dependencies after review could introduce unsafe instructions, credential-handling behavior, or executable setup logic that is not represented in the audited artifact.

The demographic Skill itself does not contain embedded malicious code, but the unpinned installation route creates a supply-chain trust boundary that exceeds what can be verified from the two local Markdown files.

### Attack Path

1. An attacker compromises the referenced package, repository, publishing account, or mutable upstream branch.
2. The attacker modifies one of the setup skills or its installation behavior.
3. A user follows the documented `npx skills add` command.
4. The current upstream content is retrieved instead of a fixed, pr
...[truncated 935 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI package and each installed skill to an immutable, reviewed version or commit hash.
  2. Publish and verify cryptographic integrity hashes or signed release metadata before installation.
  3. Avoid invoking an implicitly selected npx package version; specify a trusted version explicitly.
  4. Vendor security-sensitive setup instructions into the reviewed project where practical.
  5. Review setup-skill changes before updating pinned revisions.
  6. Run installation with minimum filesystem, network, and account permissions.
  7. Require explicit user confirmation before installing or executing externally retrieved setup content.

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:186
Finding

Remote Instructions Can Override the Audited Local Summary

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 186–190
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Medium

Vulnerable Code

markdown
- Exact schema: call `agentpmt-tool-search-and-execution` with `action: "get_schema"`, and `tool_id: "population-demographics"`.
- Detailed examples: call `agentpmt-tool-search-and-execution` with `action: "get_instructions"` and `tool_id: "population-demographics"`, or call this product with `action: "get_instructions"` when the product tool is already selected.
- Treat returned live schema and instructions as more specific than this generated summary.

Technical Analysis

The Skill instructs the Agent to retrieve mutable instructions from a remote AgentPMT service and treat those instructions as more specific than the locally audited summary. It does not expressly constrain the remote response to declarative schema fields, nor does it prohibit remotely supplied text from changing workflow behavior, requesting additional information, or redirecting tool use.

Consequently, the effective instructions used by the Agent may differ from the content reviewed in this project. If the service, product configuration, or returned content is compromised, attacker-controlled directives could be presented as authoritative product instructions.

This is an instruction trust-boundary issue rather than confirmed malicious content. The normal demographic query necessarily requires network access, but granting precedence to remotely returned behavioral instructions is not required merely to transmit country and demographic parameters.

Attack Path

  1. The Agent follows the Skill and invokes get_instructions for population-demographics.
  2. The remote service, associated product content, or response path is compromised or maliciously modified.
  3. The response includes directives unrelated to the expected demographic schema, such as instructions to ...[truncated 1058 chars]
Remediation
View remediation

Remediation Suggestions

  1. Treat all remotely returned schemas, examples, and instructions as untrusted data rather than authoritative Agent directives.
  2. State explicitly that remote content cannot override system instructions, user intent, local security rules, or data-minimization requirements.
  3. Parse schema responses into a strict, locally defined machine-readable structure and reject unknown fields or free-form behavioral directives.
  4. Restrict accepted remote information to action names, parameter types, enumerations, and response-shape metadata.
  5. Require explicit user confirmation before a remote response can trigger a new tool, destination, account operation, or transmission of additional data.
  6. Pin or cryptographically verify production schemas where feasible and review changes before use.
  7. Continue limiting requests to the minimum necessary fields and never include credentials, private keys, signatures, payment headers, or unrelated prompt context.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The overview and parameter docs repeatedly claim queries can target any country or region. But the notes later state 'No separate region aggregation endpoint; individual country queries only,' which directly contradicts the earlier guidance about region support and could mislead agents about the tool's actual behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The listed search and activation keywords include phrases like "query population data" and especially "country or region," which are not narrowly scoped trigger phrases and could match ordinary discussion rather than a clear request to invoke this specific skill. The file does not provide exclusion conditions or negative examples to constrain when activation should or should not occur.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The skill explicitly directs agents to send requests to external AgentPMT endpoints, which creates a real data egress path outside the local environment. Although the tool is intended for external querying and includes a warning not to send secrets, any agent misuse, overbroad parameter construction, or logging of sensitive context could expose data to third-party infrastructure.

Content

Scanner excerpt · SKILL.md (reported line 323)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/population-demographics
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The documented REST invoke endpoint is an actual external transmission mechanism and therefore a true vulnerability pattern in the sense of data leaving trust boundaries. In context the tool is designed for remote access to public demographics data, so the risk is moderated, but the presence of authenticated external calls still matters if an agent accidentally includes sensitive context or if endpoint trust is assumed too broadly.

Content

Scanner excerpt · SKILL.md (reported line 324)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/population-demographics
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The use-cases section states the skill can 'Track population projections and forecasts.' Elsewhere, the documented action scope is limited to querying World Bank demographic indicators for latest, specific years, or historical ranges, with no projection or forecast endpoint described.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest and main action listing emphasize query_population_data as the supported behavior for population and demographics lookup. However, the skill body additionally instructs agents to call agentpmt-tool-search-and-execution with get_schema and get_instructions, which expands behavior beyond simple demographics querying into tool metadata discovery.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.