T08 · Insecure Dependencies
- Location
SKILL.md:455- Finding
Unpinned Third-Party Packages in Setup Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent Google Drive management skill, but it grants broad Drive deletion and sharing authority without enough explicit confirmation guardrails.
Review before installing. Use this only if you are comfortable connecting AgentPMT to Google Drive with authority to search, download, upload, move, share, trash, and permanently delete files, including shared-drive content. Require explicit user confirmation for delete, trash, public/domain sharing, and sensitive downloads, and prefer pinned or ClawHub setup routes over unpinned npx commands.
SKILL.md:455Unpinned Third-Party Packages in Setup Instructions
The skill exposes a permanent delete_file action and describes it as 'not recoverable' but does not instruct agents or users to require confirmation, preview the target, or prefer trash-first workflows. In an agentic context, that omission increases the chance of irreversible destructive actions from ambiguous prompts, mis-targeting, or prompt injection routed through normal tool use.
The skill documents broad sharing operations, including type: anyone, role: reader, and discoverability options, without strong privacy warnings or guardrails. In a Google Drive context this can directly expose sensitive documents to unintended recipients or the public, especially when an agent acts on incomplete or manipulated instructions.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/google-drive
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/google-drive
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The schema exposes a permanent deletion capability that is not reflected in the manifest description, creating a dangerous mismatch between advertised and actual behavior. An agent or reviewer may assume the skill is limited to routine file management and overlook that it can irreversibly destroy Drive content, increasing the risk of unsafe invocation or overbroad trust.
Destructive and sharing-capable operations are presented without explicit warnings about privacy and data-loss consequences, which can lead an agent or user to invoke them without appreciating the risk. In a Google Drive skill, actions like permanent delete and permission changes directly affect confidentiality, integrity, and availability of user data, making omission of warnings materially unsafe.
The upload action can fetch content from arbitrary public URLs, but this behavior is not disclosed in the manifest, masking that the skill can act as an external network fetcher and data-ingestion bridge into Drive. This expands the attack surface by enabling retrieval of attacker-controlled content, possible SSRF-style misuse depending on fetcher implementation, and unreviewed import of malicious or sensitive data into the user's Drive.
The skill includes trashing capability that is omitted from the manifest description, so consumers may underestimate that it can remove user data from normal visibility. Although trashing is recoverable, it can still disrupt workflows, hide files, or facilitate unauthorized data manipulation when agents are granted the skill under incomplete assumptions.
No suspicious patterns detected.