Back to skill

Security audit

Network Tools

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent remote AgentPMT network-utility integration, but it can send sensitive network details to a third party with limited per-action privacy warnings and uses unpinned setup-install commands.

Review this carefully before installing in enterprise, incident-response, or private-network contexts. Do not submit internal hostnames, private CIDRs, MAC addresses, customer IPs, or other sensitive topology unless you intend to share them with AgentPMT and accept any account-credit cost. Prefer pinned, verified setup paths where available.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:387
Finding

Potential Disclosure of Sensitive Network Topology to a Remote Service

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:357
Finding

Unpinned Third-Party Setup Skill Installation Creates Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The DNS lookup action sends supplied hostnames to a remote AgentPMT-hosted service, but the action description does not clearly warn users that lookup targets will leave the local environment. This creates a privacy and operational security risk because internal hostnames, investigation targets, or sensitive infrastructure identifiers may be disclosed externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The reverse DNS action transmits user-supplied IP addresses to a remote service without a clear per-action warning. This can expose sensitive IPs from internal investigations, asset inventories, or incident response workflows to an external provider.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation keywords include generic terms such as input and broad networking phrases, which can cause the skill to match unrelated prompts and be invoked unintentionally. In an agent environment, accidental invocation can route user data to a remote service or alter workflow decisions without clear user intent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill is explicitly designed to invoke remote AgentPMT endpoints, meaning user-provided networking data may be transmitted outside the local trust boundary. In this context, external transmission is expected functionality, but it is still security-relevant because inputs such as hostnames, IPs, and potentially workflow metadata can be exposed to a third party.

Content

Scanner excerpt · SKILL.md (reported line 417)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/network-tools
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The REST invoke endpoint confirms that this skill depends on external network calls to process requests. That is not inherently malicious, but it is a real data-exposure risk in agent workflows if users assume these utilities run locally or fail to realize that request contents are sent to a remote service.

Content

Scanner excerpt · SKILL.md (reported line 418)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/network-tools
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The network-dns-lookup action causes user-supplied hostnames to be resolved via external DNS infrastructure, which can disclose sensitive internal hostnames or investigation targets to third parties. In an agent setting, this is a real privacy and data-handling issue because users may not realize that apparently simple lookup inputs are transmitted off-box/network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The network-reverse-dns action sends the provided IP address to DNS infrastructure to perform a PTR lookup, which can reveal sensitive target IPs or internal investigation activity. While the functionality is expected for the tool, the lack of disclosure increases the risk of unintended data exposure in privacy-sensitive or enterprise contexts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.