T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:87- Finding
Third-Party Generation and Handling of Production Authentication Secrets
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is review-worthy because it uses a third-party service to generate sensitive authentication tokens and relies on mutable setup paths.
Install only if you are comfortable with AgentPMT generating values that may become credentials. For production API keys, session IDs, password-reset tokens, passwords, and 2FA secrets, prefer local OS CSPRNG generation or a design where the provider never sees the final secret. If you use this skill, keep requests minimal, avoid logging generated tokens, verify the provider's retention and logging controls, and pin or audit any setup skills before running npx-based installs.
SKILL.md:87Third-Party Generation and Handling of Production Authentication Secrets
SKILL.md:188Unpinned Third-Party Package Execution During Setup
The activation keywords include very broad terms such as generate, length, and charset, which can cause the skill to match unrelated prompts. In an agent environment, overbroad routing can trigger unintended external tool use and unnecessary transmission of task context to third-party services.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill explicitly directs agents to send requests to external AgentPMT endpoints, which creates a real data-exposure boundary. Although the skill warns not to send secrets, unintended invocation or operator misuse could still result in sensitive metadata, prompts, or token-related context being transmitted off-platform.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/quantum-secure-token-generator
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The REST invoke endpoint is an actual outbound network destination for tool execution, so this is a legitimate external-transmission finding. In context the tool is meant to call a remote service, but that still introduces confidentiality and dependency risk if agents over-share data or invoke the endpoint unexpectedly.
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/quantum-secure-token-generator
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
No suspicious patterns detected.