T09 · Insecure Skill Coding Practices
- Location
SKILL.md:387- Finding
Potential Disclosure of Sensitive Network Topology to a Remote Service
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent remote AgentPMT network-utility integration, but it can send sensitive network details to a third party with limited per-action privacy warnings and uses unpinned setup-install commands.
Review this carefully before installing in enterprise, incident-response, or private-network contexts. Do not submit internal hostnames, private CIDRs, MAC addresses, customer IPs, or other sensitive topology unless you intend to share them with AgentPMT and accept any account-credit cost. Prefer pinned, verified setup paths where available.
SKILL.md:387Potential Disclosure of Sensitive Network Topology to a Remote Service
SKILL.md:357Unpinned Third-Party Setup Skill Installation Creates Supply-Chain Risk
The DNS lookup action sends supplied hostnames to a remote AgentPMT-hosted service, but the action description does not clearly warn users that lookup targets will leave the local environment. This creates a privacy and operational security risk because internal hostnames, investigation targets, or sensitive infrastructure identifiers may be disclosed externally.
The reverse DNS action transmits user-supplied IP addresses to a remote service without a clear per-action warning. This can expose sensitive IPs from internal investigations, asset inventories, or incident response workflows to an external provider.
The activation keywords include generic terms such as input and broad networking phrases, which can cause the skill to match unrelated prompts and be invoked unintentionally. In an agent environment, accidental invocation can route user data to a remote service or alter workflow decisions without clear user intent.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill is explicitly designed to invoke remote AgentPMT endpoints, meaning user-provided networking data may be transmitted outside the local trust boundary. In this context, external transmission is expected functionality, but it is still security-relevant because inputs such as hostnames, IPs, and potentially workflow metadata can be exposed to a third party.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/network-tools
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The REST invoke endpoint confirms that this skill depends on external network calls to process requests. That is not inherently malicious, but it is a real data-exposure risk in agent workflows if users assume these utilities run locally or fail to realize that request contents are sent to a remote service.
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/network-tools
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The network-dns-lookup action causes user-supplied hostnames to be resolved via external DNS infrastructure, which can disclose sensitive internal hostnames or investigation targets to third parties. In an agent setting, this is a real privacy and data-handling issue because users may not realize that apparently simple lookup inputs are transmitted off-box/network.
The network-reverse-dns action sends the provided IP address to DNS infrastructure to perform a PTR lookup, which can reveal sensitive target IPs or internal investigation activity. While the functionality is expected for the tool, the lack of disclosure increases the risk of unintended data exposure in privacy-sensitive or enterprise contexts.
No suspicious patterns detected.