Back to skill

Security audit

Markitdown Hosted Markdown Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a hosted document-to-Markdown connector with privacy and supply-chain cautions, but the inspected artifacts do not show hidden, destructive, or deceptive behavior.

Use this skill only with files, audio, images, archives, and URLs that you are allowed to send to AgentPMT for hosted processing. Avoid secrets, regulated data, internal-only links, and signed URLs unless you have explicit approval. For production use, prefer vetted or pinned installs of related setup skills instead of floating npx commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:193
Finding

Unpinned third-party installation commands create a mutable supply-chain execution path

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 193-209
Vulnerability Type: Unpinned executable package and Skill dependencies
Risk Level: Medium

Vulnerable Code

markdown
Core AgentPMT setup skills:
- What AgentPMT is: ../what-is-agentpmt
  - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt
  - OpenClaw install: `openclaw skills install what-is-agentpmt`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup
  - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup
  - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`

skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
text

### Technical Analysis

The documented `npx skills add` commands do not pin the `skills` CLI to an audited version. They also identify the `AgentPMT/agent-skills` source without an immutable commit, release digest, checksum, or signature. Consequently, the content retrieved and processed when a user follows these instructions can differ from the content available when this Skill was reviewed.

`npx` can download and execute a Node.js package when the package is not already installed locally. This creates a code-execution boundary involving mutable third-party infrastructure. The downstream Skill repository is also outside this artifact and was not available for audit. Although no evidence establishes that either dependency is currently malicious, the installation method exposes users to package-account compromise, repository compromise, malicious release replacement, and other supply-chain attacks.

### Attack Path

...[truncated 1475 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a reviewed exact version, for example by using an explicit immutable package version rather than allowing npx to resolve the latest release.
  2. Pin AgentPMT/agent-skills to an immutable commit hash or cryptographically signed release instead of a mutable repository reference.
  3. Publish and verify SHA-256 checksums or signed provenance for all downloaded artifacts before execution.
  4. Use npx options and package-manager configuration that prevent unexpected version resolution and lifecycle-script execution where compatible with the installer.
  5. Vendor reviewed setup instructions or dependencies into a controlled distribution when practical.
  6. Execute installation in a sandbox or least-privileged environment without unrelated credentials or sensitive filesystem access.
  7. Document the exact trusted publisher, version, commit, checksum, and verification procedure so users can independently validate the dependency chain.
  8. Re-audit the pinned dependencies whenever their versions or immutable references change.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill describes converting files and URLs but does not prominently warn that document contents, image/audio data, or fetched URLs are transmitted to a hosted third-party service. This undermines informed consent and can lead to accidental exfiltration of sensitive data through normal skill use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation keywords include very broad terms such as convert and url, which can cause the skill to trigger in unrelated contexts. Over-broad activation increases the chance that arbitrary user files or links are sent to this remote service unintentionally.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

The skill instructs users to install or refresh supporting skills via npx skills ... without pinning an exact package or repository version. This creates a supply-chain risk: future upstream changes or a compromised package/source could alter the installed code or instructions unexpectedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

This line references an unpinned npx skills installation flow for a dependency skill. Unpinned remote installs allow silent drift and potential malicious substitution if the upstream registry entry or referenced content changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

The skill recommends reinstalling from remote sources using npx skills but does not constrain the version being fetched. In an agent ecosystem, that can lead to nondeterministic behavior and exposure to compromised or newly risky upstream skill definitions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

The referenced installation command uses npx skills with no pinned version, leaving the fetched tooling and skill content subject to upstream change. That increases the attack surface for supply-chain compromise or unexpected behavior changes over time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

This is another unpinned remote install instruction for a related setup skill. Because the skill is specifically about enabling remote tool calls, allowing floating installation inputs increases the chance of importing altered configuration or malicious instructions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

The npx skills command on this line is unpinned and therefore susceptible to upstream tampering or breaking changes. In practice, an operator could unknowingly install modified skill logic that affects how credentials or remote calls are handled.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

This line continues the same unpinned install pattern for a prerequisite skill. While common in documentation, it is still a real supply-chain weakness because the instructions normalize fetching mutable remote content in a privileged workflow path.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

The reference to npx skills add ... is not version constrained, so anyone following the skill may pull a changed artifact later. Since these setup skills affect account and MCP connectivity, compromise here could have downstream security consequences.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

This unpinned installer reference poses the same supply-chain risk as the other occurrences. The danger is elevated slightly by context because the installed skill is related to account setup and remote API connectivity, which can influence credential handling and execution paths.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/markitdown
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 266)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/markitdown
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The schema explicitly supports sending either raw file contents (file_base64) or a remote url to a hosted conversion service, but it does not warn users that document contents and referenced resources will be transmitted to an external system. This creates a real risk of unintended disclosure of sensitive files, internal signed URLs, or private documents, especially when invoked by an agent on a user's behalf.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.