Back to skill

Security audit

Project Task Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent AgentPMT project-planning integration, but its broad activation wording plus persistent, billable third-party task storage warrants careful review before use.

Install only if you intend to use AgentPMT for task planning and are comfortable sending project objectives, context, task notes, and progress to its hosted service for persistent storage and paid credit usage. Avoid secrets, credentials, private keys, customer data, incident details, or regulated information in task text, and prefer pinned or verified install sources instead of unpinned npx fallback commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:285
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description uses broad discovery language such as decompose and task, increasing the chance that an orchestrator selects this remote skill for commonplace planning requests. Because this skill routes data to a third-party service and incurs credits, accidental invocation has privacy, integrity, and billing consequences beyond mere inconvenience.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation keywords include very generic terms such as decompose, task, and level of detail, which can match many unrelated user requests. In an agentic environment, overly broad triggers can cause unintended tool invocation, leading to unnecessary transmission of user/project content to the remote AgentPMT service and unexpected paid actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The skill is explicitly designed to send objectives, context, task notes, and progress data to external AgentPMT endpoints over MCP/REST. That is a real data egress surface: project details may include sensitive business plans, internal architecture, or operational notes, and persistence across sessions increases exposure if the wrong content is sent.

Content

Scanner excerpt · SKILL.md (reported line 338)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/project-task-manager
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The REST invocation endpoint enables external transmission of the same project/task content to a third-party service. In context, this is expected product behavior, but it is still security-relevant because routine planning text can contain confidential roadmap, customer, infrastructure, or incident information that becomes stored outside the local environment.

Content

Scanner excerpt · SKILL.md (reported line 339)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/project-task-manager
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description says to use only 'in_progress', 'completed', 'failed', or 'blocked', but the generated enum explicitly includes 'pending'. This is an active documentation-to-schema contradiction rather than a mere omission, because the text describes the valid values for the field and conflicts with what the schema actually accepts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.