T08 · Insecure Dependencies
- Location
SKILL.md:285- Finding
Unpinned Third-Party Package Execution Through npx
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent AgentPMT project-planning integration, but its broad activation wording plus persistent, billable third-party task storage warrants careful review before use.
Install only if you intend to use AgentPMT for task planning and are comfortable sending project objectives, context, task notes, and progress to its hosted service for persistent storage and paid credit usage. Avoid secrets, credentials, private keys, customer data, incident details, or regulated information in task text, and prefer pinned or verified install sources instead of unpinned npx fallback commands.
SKILL.md:285Unpinned Third-Party Package Execution Through npx
The manifest description uses broad discovery language such as decompose and task, increasing the chance that an orchestrator selects this remote skill for commonplace planning requests. Because this skill routes data to a third-party service and incurs credits, accidental invocation has privacy, integrity, and billing consequences beyond mere inconvenience.
The activation keywords include very generic terms such as decompose, task, and level of detail, which can match many unrelated user requests. In an agentic environment, overly broad triggers can cause unintended tool invocation, leading to unnecessary transmission of user/project content to the remote AgentPMT service and unexpected paid actions.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill is explicitly designed to send objectives, context, task notes, and progress data to external AgentPMT endpoints over MCP/REST. That is a real data egress surface: project details may include sensitive business plans, internal architecture, or operational notes, and persistence across sessions increases exposure if the wrong content is sent.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/project-task-manager
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The REST invocation endpoint enables external transmission of the same project/task content to a third-party service. In context, this is expected product behavior, but it is still security-relevant because routine planning text can contain confidential roadmap, customer, infrastructure, or incident information that becomes stored outside the local environment.
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/project-task-manager
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The description says to use only 'in_progress', 'completed', 'failed', or 'blocked', but the generated enum explicitly includes 'pending'. This is an active documentation-to-schema contradiction rather than a mere omission, because the text describes the valid values for the field and conflicts with what the schema actually accepts.
No suspicious patterns detected.