Back to skill

Security audit

Minecraft Custom Mod Builder

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent remote Minecraft mod builder, but it also supports abuse-prone client/ESP features and uses mutable setup commands, so it belongs in Review before installation.

Install only if you are comfortable with a third-party hosted service receiving Minecraft specs, images, and optional source archives, and avoid using it for multiplayer cheating, griefing, surveillance, or private code/assets unless you have reviewed the AgentPMT setup and storage terms. Prefer pinned installation commands or trusted OpenClaw installation paths where available, and keep credentials, wallet secrets, and payment headers out of prompts and logs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:1273
Finding

Unpinned Third-Party Setup Dependencies Can Execute Mutable Upstream Code

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 1273–1277
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

bash
skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
npx skills add AgentPMT/agent-skills --skill agentpmt-no-account-agentaddress-x402

Technical Analysis

The documented setup procedure invokes npx without pinning the skills CLI package or the AgentPMT/agent-skills repository to an immutable package version, release artifact, or commit hash. Consequently, the code and content resolved when a user follows these instructions may differ from what was available when this Skill was audited.

This creates a supply-chain trust boundary in which compromise of the package registry entry, source repository, maintainer account, or a later upstream release could introduce attacker-controlled code. Because npx executes the resolved CLI locally, malicious package initialization or CLI code could run with the privileges of the user performing the installation.

Attack Path

  1. An attacker compromises an upstream package, repository, release process, or maintainer account used by the documented commands.
  2. The attacker publishes a malicious version or modifies the mutable upstream source.
  3. A user follows the setup instructions and runs one of the unpinned npx skills add commands.
  4. npx resolves and executes the current third-party CLI package rather than an audited immutable version.
  5. The malicious dependency executes in the user's environment or installs attacker-controlled Skill instructions for subsequent use.

Impact Assessment

Successful exploitation could provide code execution with the permissions of the user running npx. Depending on the execution environment and its existing controls, this may permit ...[truncated 614 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the skills CLI to a reviewed exact version instead of relying on the version selected dynamically by npx.
  2. Pin AgentPMT/agent-skills to an immutable commit hash or signed release rather than a mutable repository reference.
  3. Publish and verify cryptographic checksums or signatures for downloaded installation artifacts.
  4. Use package-lock or equivalent integrity metadata where supported.
  5. Disable dependency lifecycle scripts where they are unnecessary, and document any scripts that must execute.
  6. Run installation in a sandbox with minimal filesystem, credential, and network access.
  7. Provide users with a verification procedure showing the expected package version, repository commit, signer identity, and artifact checksum before execution.
  8. Review and repin dependencies through a controlled update process whenever upstream versions change.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill advertises generation of installable mods and edited source, including prank/chaos/admin/debug mechanics and agent-edited code workflows, without an upfront warning about destructive, unsafe, or policy-sensitive outputs. In this context, the absence of an early safety boundary makes misuse more likely because the tool can produce artifacts that affect third-party multiplayer environments or execute custom behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly supports generating 'anarchy/utility' and 'hacked client' style Java modules, including ESP-style scanning and client-side utility behavior. That meaningfully expands the tool from ordinary mod building into cheat-client enablement, which can facilitate abuse on multiplayer servers and reduce the safety boundary expected from a general-purpose mod builder.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation keywords are broad enough to trigger the skill in contexts that are not narrowly scoped to safe Minecraft mod-building tasks. Over-broad discovery increases the chance that an agent routes arbitrary software-generation or harmful mod requests into this powerful remote build-and-package service.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1345)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- No-account AgentAddress/x402 setup: ../agentpmt-no-account-agentaddress-x402 (ClawHub: `agentpmt-no-account-agentaddress-x402`, page: https://clawhub.ai/agentpmt/agentpmt-no-account-agentaddress-x402; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-no-account-agentaddress-x402`)
- Marketplace product: https://www.agentpmt.com/marketplace/minecraft-custom-mod-builder
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1346)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- No-account AgentAddress/x402 setup: ../agentpmt-no-account-agentaddress-x402 (ClawHub: `agentpmt-no-account-agentaddress-x402`, page: https://clawhub.ai/agentpmt/agentpmt-no-account-agentaddress-x402; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-no-account-agentaddress-x402`)
- Marketplace product: https://www.agentpmt.com/marketplace/minecraft-custom-mod-builder
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The schema explicitly states that x402 action routes are enabled through a remote AgentPMT endpoint and several actions accept uploaded file IDs or return hosted artifacts, but it does not clearly warn users that mod specs, source archives, and related content are transmitted to an external service. This can lead to unintentional disclosure of proprietary code, assets, or sensitive project data when an agent invokes the skill under the assumption that processing is local.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.