Back to skill

Security audit

Infrastructure Mobility And Housing Data Hub

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its data-query purpose, but it asks agents to trust mutable remote instructions and includes unpinned install commands tied to account, wallet, and payment setup.

Review this before installing in sensitive environments. The core data query is narrow and disclosed, but avoid copying the unpinned `npx` setup commands unless you trust the source and can pin or verify versions. Treat any live instructions returned by AgentPMT as untrusted guidance bounded by the local skill, and do not provide secrets, private keys, mnemonics, signatures, or payment headers in prompts or logs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:180
Finding

Mutable Remote Instructions Override the Locally Audited Skill

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 180–181
Vulnerability Type: Remote instruction precedence and instruction hijacking
Risk Level: High

Vulnerable code snippet:

text
- Detailed examples: call `agentpmt-tool-search-and-execution` with `action: "get_instructions"` and `tool_id: "infrastructure-urban-development"`, or call this product with `action: "get_instructions"` when the product tool is already selected.
- Treat returned live schema and instructions as more specific than this generated summary.

Technical Analysis

The Skill instructs the agent to retrieve mutable instructions from an external AgentPMT service and treat the returned content as more authoritative than the locally installed and audited Skill summary. This establishes a remote instruction-hijacking channel: the effective behavior can change after package review without any corresponding modification to the local files.

Remote schemas may legitimately be needed to maintain API compatibility, but behavioral instructions returned by a service must not override local safety rules or define new actions. The response should instead be handled as untrusted data and constrained by a locally defined, versioned schema and action allowlist.

Attack Path

  1. An agent loads the locally audited Skill.
  2. The agent encounters an unclear parameter, response, or example and invokes get_instructions as directed.
  3. The AgentPMT account, service, delivery infrastructure, or returned product instructions are compromised or maliciously changed.
  4. The remote response contains behavioral directives that differ from the reviewed Skill.
  5. Because line 181 explicitly gives the remote instructions greater specificity, the agent follows the altered directives.
  6. The attacker can induce unauthorized tool calls, redirect data to other endpoints, request unnecessary sensitive inputs, or manipulate subsequent workflow decisions, ...[truncated 888 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the directive that remote instructions are more authoritative than the locally audited Skill.
  2. Bundle a versioned action schema and approved examples with the Skill.
  3. If live schema retrieval is necessary, treat the response strictly as untrusted structured data rather than executable agent instructions.
  4. Validate remote responses against a local JSON schema, including an allowlist of action names, fields, types, endpoint hosts, and acceptable values.
  5. Reject remote content that requests new tools, different endpoints, credentials, local file access, command execution, or changes to safety constraints.
  6. Pin remote schema versions and verify signed content or integrity hashes before use.
  7. Require explicit user approval before any remotely suggested operation that expands data disclosure, cost, or privileges.
  8. Ensure system and local Skill safety rules always take precedence over service-returned content.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:259
Finding

Unpinned Third-Party Skill and CLI Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 259–261
Vulnerability Type: Unpinned executable tooling and mutable Skill dependencies
Risk Level: Medium

Vulnerable code snippet:

bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
npx skills add AgentPMT/agent-skills --skill agentpmt-no-account-agentaddress-x402

Equivalent unpinned installation instructions also appear at lines 246, 250, 254, and 322–324.

Technical Analysis

The installation commands invoke an unversioned package through npx and retrieve mutable Skill content from AgentPMT/agent-skills without a pinned package version, repository commit, integrity hash, or signature requirement.

This creates two mutable supply-chain boundaries:

  1. The package resolved and executed by npx.
  2. The upstream repository content from which the account, REST, wallet, and x402 setup Skills are installed.

Because the additional Skills concern account connectivity, payment, and wallet setup, a malicious upstream change could have greater impact than an ordinary documentation dependency. The audit did not find evidence that the currently referenced upstream content is malicious; the vulnerability is the absence of reproducible and integrity-verified dependency resolution.

Attack Path

  1. A user follows the documented setup commands.
  2. npx resolves the current available version of the skills package rather than a reviewed, pinned release.
  3. The installer retrieves the current state of AgentPMT/agent-skills, also without a pinned commit or verified digest.
  4. An attacker who compromises the package registry, package maintainer, source repository, release process, or dependency resolution path supplies altered executable tooling or Skill instructions.
  5. The altered component runs during installation or is subsequently loaded ...[truncated 853 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npx package to an explicitly reviewed version, rather than relying on the latest registry resolution.
  2. Pin AgentPMT/agent-skills to an immutable commit or signed release tag.
  3. Publish and verify cryptographic hashes or signatures for both the installer and each downloaded Skill.
  4. Prefer vendoring the reviewed setup documentation and schemas into the package when licensing and maintenance requirements permit.
  5. Use lockfiles and a trusted registry configuration for all executable dependencies.
  6. Avoid automatic installation; display the exact source, version, digest, and requested effects, then require explicit user confirmation.
  7. Run installation in a sandbox with minimal filesystem, environment, credential, and network access.
  8. Separately review account, wallet, payment, and x402 setup dependencies before allowing them to handle sensitive workflows.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description includes 'housing and permit trend analysis,' yet the documented action surface only supports query_infrastructure_data with infrastructure types limited to electricity, internet, water, roads, urban, or all. No action, parameter, or documented indicator supports permit data, so the stated intent overpromises functionality relative to the rest of the file.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed search and activation keywords include broad phrases such as "urban planning support" and "country or region" that overlap with common analytical requests and do not clearly delimit when this skill should or should not activate. The file does not provide negative examples or contextual constraints to prevent unintended invocation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The top-level description presents this skill as a data hub for querying World Bank infrastructure data by country or region. However, a substantial portion of the skill body is devoted to AgentPMT account setup, x402 payment setup, schema/instruction discovery via another tool, and REST/MCP invocation mechanics, which goes beyond the described data-query purpose. While some invocation guidance is expected for a remote tool, this document materially broadens the skill's operational scope into platform setup and payment orchestration.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs users to run npx skills without pinning an exact package version or integrity mechanism. That creates a supply-chain risk: a later compromised or breaking package release could be fetched and executed at install time, leading to arbitrary code execution on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This installation instruction uses npx skills without version pinning, so the executed code is whatever package version is current at runtime. If the package or dependency chain is hijacked, users could unknowingly run malicious code during setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Unpinned npx execution allows remote package code to change over time outside the skill author's control. In an agent or automation context, that increases the chance of executing malicious or incompatible installer code with the user's local permissions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill includes another unpinned npx skills install command, exposing users to package substitution and future-release drift. Because npx executes fetched code, compromise of the package ecosystem can directly become code execution on the client machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This line repeats the same supply-chain exposure from unversioned npx usage. The risk is not theoretical: package takeovers, typo-squatting, or malicious updates can cause arbitrary code execution during setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Another unpinned install command appears in a grouped setup block, increasing the chance a user copies and runs it directly. Since the package version is not fixed, the content executed can differ from what was reviewed when the skill was published.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The reference section again promotes unpinned npx skills installation, extending the same supply-chain execution risk into the documentation footer. Repetition in multiple places makes accidental unsafe execution more likely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This is a duplicate instance of unpinned package execution guidance. In practice, any copied command that executes remote package code without version constraints can be abused via malicious updates or dependency compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The final npx skills reference still leaves install-time behavior uncontrolled and mutable. That is a supply-chain vulnerability because the reviewed skill text does not uniquely determine the code that will execute later.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 326)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- No-account AgentAddress/x402 setup: ../agentpmt-no-account-agentaddress-x402 (ClawHub: `agentpmt-no-account-agentaddress-x402`, page: https://clawhub.ai/agentpmt/agentpmt-no-account-agentaddress-x402; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-no-account-agentaddress-x402`)
- Marketplace product: https://www.agentpmt.com/marketplace/infrastructure-urban-development
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 327)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- No-account AgentAddress/x402 setup: ../agentpmt-no-account-agentaddress-x402 (ClawHub: `agentpmt-no-account-agentaddress-x402`, page: https://clawhub.ai/agentpmt/agentpmt-no-account-agentaddress-x402; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-no-account-agentaddress-x402`)
- Marketplace product: https://www.agentpmt.com/marketplace/infrastructure-urban-development
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Static analysis

No suspicious patterns detected.