T08 · Insecure Dependencies
- Location
SKILL.md:39- Finding
Unpinned npm Package Is Installed and Executed Locally
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent AgentPMT setup guide, but it asks users to run unpinned local packages and store spending-authorized credentials in persistent agent configuration with insufficient warnings.
Review this before installing. Prefer manual per-client setup, avoid global installation, pin an exact reviewed package version instead of @latest, keep bearer tokens out of project files and source control, use the narrowest budget key and spending cap available, and rotate keys immediately if the token appears in logs, shell history, screenshots, or a repository.
SKILL.md:39Unpinned npm Package Is Installed and Executed Locally
SKILL.md:51Reversible API and Budget Credentials Are Stored in Plaintext Configuration
SKILL.md:32Automatic Setup Requires Broad Configuration and Process-Control Access
The skill directs modification of sensitive MCP configuration locations such as project .mcp.json and global ~/.claude/mcp.json, which can change what tools an agent is allowed to invoke and persist trust relationships. Because these files can affect future agent behavior and may expose tokens to local processes or repositories if mishandled, this is a meaningful security-sensitive action.
Claude Code
Add to the project's .mcp.json or the global ~/.claude/mcp.json:
{
The description says to use this skill for 'any AI agent' and when the user mentions broad concepts like 'MCP server configuration' or 'connecting an AI agent to paid tools and APIs.' Those phrases are expansive and overlap with many unrelated setup requests, which can cause unintended invocation because the trigger scope is not tightly constrained to explicit AgentPMT-specific phrasing.
The skill claims the STDIO connector 'does not execute anything on the user's machine,' but the documented setup explicitly installs and runs local code via npm, npx, and agentpmt-setup. This is materially misleading because users may underestimate the risk of executing a package fetched from the network and allowing it to modify local MCP/client configuration.
The skill instructs users to edit MCP/client config files, restart applications, and provide credentials that will be transmitted to a third-party service, but it does not prominently warn about those system and privacy consequences. This can lead users to make security-sensitive changes without informed consent or understanding of credential exposure and trust boundaries.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
For agents that support remote MCP servers over HTTP, connect directly without the local connector.
**Endpoint:** `https://api.agentpmt.com/mcp`
**Protocol:** MCP 2.0 (JSON-RPC over streamable HTTP)
The curl initialization example sends a bearer token to a remote service and may encourage users to paste secrets directly into commands, which can leak via shell history, logs, or screenshots. In the context of a marketplace tied to budgets and paid tools, token compromise could enable unauthorized tool usage within budget limits.
curl -X POST https://api.agentpmt.com/mcp \
-H "Authorization: Bearer <your-base64-token>" \
-H "Content-Type: application/json" \
-d '{
The curl initialization example sends a bearer token to a remote service and may encourage users to paste secrets directly into commands, which can leak via shell history, logs, or screenshots. In the context of a marketplace tied to budgets and paid tools, token compromise could enable unauthorized tool usage within budget limits.
curl -X POST https://api.agentpmt.com/mcp \
-H "Authorization: Bearer <your-base64-token>" \
-H "Content-Type: application/json" \
-d '{
The tools/list example also performs authenticated external transmission and normalizes sending a spending-authorized token to a third-party service. While expected for functionality, the missing security guidance increases the chance of accidental credential disclosure or misuse.
curl -X POST https://api.agentpmt.com/mcp \
-H "Authorization: Bearer <your-base64-token>" \
-H "Content-Type: application/json" \
-d '{
The tools/call example is more sensitive because it not only authenticates to the remote service but demonstrates invoking billable or capability-bearing tools. If the token is exposed, an attacker could trigger unauthorized tool calls and consume budget or access approved external services.
curl -X POST https://api.agentpmt.com/mcp \
-H "Authorization: Bearer <your-base64-token>" \
-H "Content-Type: application/json" \
-d '{
Embedding the Authorization header directly into persistent client configuration increases the risk of long-lived secret exposure to local users, backups, logs, or accidental repository commits. In MCP configs, this can silently grant ongoing remote tool access whenever the client starts.
{
"mcpServers": {
"agentpmt": {
"url": "https://api.agentpmt.com/mcp",
"headers": {
"Authorization": "Bearer <your-base64-token>"
}
No suspicious patterns detected.