Back to skill

Security audit

Install Agentpmt Mcp

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent AgentPMT setup guide, but it asks users to run unpinned local packages and store spending-authorized credentials in persistent agent configuration with insufficient warnings.

Review this before installing. Prefer manual per-client setup, avoid global installation, pin an exact reviewed package version instead of @latest, keep bearer tokens out of project files and source control, use the narrowest budget key and spending cap available, and rotate keys immediately if the token appears in logs, shell history, screenshots, or a repository.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Error
Location
SKILL.md:39
Finding

Unpinned npm Package Is Installed and Executed Locally

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:51
Finding

Reversible API and Budget Credentials Are Stored in Plaintext Configuration

Content
View full analysis
" } } } } ``` For remote MCP clients, it similarly places the token directly in a header configuration: ```json { "mcpServers": { "agentpmt": { "url": "https://api.agentpmt.com/mcp", "headers": { "Authorization": "Bearer " } } } } ``` ### Technical Analysis Base64 provides encoding, not encryption. Anyone who obtains the configured bearer token can trivially decode it into the underlying API key and budget key. The instructions permit storing this combined credential in either a project-level `.mcp.json` file or global client configuration. Project-level files are particularly exposed to accidental source-control commits, repository sharing, project indexing, extensions, backup systems, and unrelated tooling operating within the workspace. Global configuration can expose the token to every workspace or process able to read that client configuration. The Skill does not instruct users to use an operating-system credential store, secret manager, protected environment injection, restrictive file permissions, or source-control exclusion. It also does not explicitly warn that the Base64 value is fully reversible or provide redaction guidance for logs and support requests. ### Attack Path 1. A user creates the token by Base64-encodin ...[truncated 1287 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:32
Finding

Automatic Setup Requires Broad Configuration and Process-Control Access

Content
View full analysis
The setup tool auto-detects installed AI platforms, prompts for credentials, writes the configuration files, and restarts the AI tools. The Skill also makes the following broad claim about the connector: > The local STDIO connector (`@agentpmt/mcp-router`) is a thin relay. It does not access local files, does not execute code on the user's machine, and does not cache credentials beyond the current session. All tool execution happens on AgentPMT's cloud infrastructure. ### Technical Analysis Automatic setup necessarily performs local operations beyond simple network relaying: it enumerates installed AI clients, receives sensitive credentials, writes one or more local configuration files, and restarts client processes. Those permissions are broader than the minimum required by the documented manual installation method, where the user can choose and modify a single client configuration. The assertion that the connector does not access local files or execute anything on the user's machine is ambiguous when presented alongside an automatic setup utility that explicitly writes files and restarts applications. The text may intend to distinguish the runtime relay from the setup utility, but it does not clearly establish that boundary. Because the npm implementation is not included in the project, the audit cannot verify which clients are enumerated, which files are read or changed, how credentials are handled during setup, or how restart operations are implemented. The concern is therefore excessive and insufficiently documented privilege rather than ...[truncated 1474 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

MCP Config Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

The skill directs modification of sensitive MCP configuration locations such as project .mcp.json and global ~/.claude/mcp.json, which can change what tools an agent is allowed to invoke and persist trust relationships. Because these files can affect future agent behavior and may expose tokens to local processes or repositories if mishandled, this is a meaningful security-sensitive action.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

Claude Code

Add to the project's .mcp.json or the global ~/.claude/mcp.json:

json
{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description says to use this skill for 'any AI agent' and when the user mentions broad concepts like 'MCP server configuration' or 'connecting an AI agent to paid tools and APIs.' Those phrases are expansive and overlap with many unrelated setup requests, which can cause unintended invocation because the trigger scope is not tightly constrained to explicit AgentPMT-specific phrasing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill claims the STDIO connector 'does not execute anything on the user's machine,' but the documented setup explicitly installs and runs local code via npm, npx, and agentpmt-setup. This is materially misleading because users may underestimate the risk of executing a package fetched from the network and allowing it to modify local MCP/client configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs users to edit MCP/client config files, restart applications, and provide credentials that will be transmitted to a third-party service, but it does not prominently warn about those system and privacy consequences. This can lead users to make security-sensitive changes without informed consent or understanding of credential exposure and trust boundaries.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
For agents that support remote MCP servers over HTTP, connect directly without the local connector.

**Endpoint:** `https://api.agentpmt.com/mcp`

**Protocol:** MCP 2.0 (JSON-RPC over streamable HTTP)

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The curl initialization example sends a bearer token to a remote service and may encourage users to paste secrets directly into commands, which can leak via shell history, logs, or screenshots. In the context of a marketplace tied to budgets and paid tools, token compromise could enable unauthorized tool usage within budget limits.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

Example: Initialize Connection

bash
curl -X POST https://api.agentpmt.com/mcp \
  -H "Authorization: Bearer <your-base64-token>" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The curl initialization example sends a bearer token to a remote service and may encourage users to paste secrets directly into commands, which can leak via shell history, logs, or screenshots. In the context of a marketplace tied to budgets and paid tools, token compromise could enable unauthorized tool usage within budget limits.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

Example: Initialize Connection

bash
curl -X POST https://api.agentpmt.com/mcp \
  -H "Authorization: Bearer <your-base64-token>" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The tools/list example also performs authenticated external transmission and normalizes sending a spending-authorized token to a third-party service. While expected for functionality, the missing security guidance increases the chance of accidental credential disclosure or misuse.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

Example: List Available Tools

bash
curl -X POST https://api.agentpmt.com/mcp \
  -H "Authorization: Bearer <your-base64-token>" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The tools/call example is more sensitive because it not only authenticates to the remote service but demonstrates invoking billable or capability-bearing tools. If the token is exposed, an attacker could trigger unauthorized tool calls and consume budget or access approved external services.

Content

Scanner excerpt · SKILL.md (reported line 186)May include surrounding context.

Example: Call a Tool

bash
curl -X POST https://api.agentpmt.com/mcp \
  -H "Authorization: Bearer <your-base64-token>" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

Embedding the Authorization header directly into persistent client configuration increases the risk of long-lived secret exposure to local users, backups, logs, or accidental repository commits. In MCP configs, this can silently grant ongoing remote tool access whenever the client starts.

Content

Scanner excerpt · SKILL.md (reported line 208)May include surrounding context.

md
{
  "mcpServers": {
    "agentpmt": {
      "url": "https://api.agentpmt.com/mcp",
      "headers": {
        "Authorization": "Bearer <your-base64-token>"
      }

Static analysis

No suspicious patterns detected.