Back to skill

Security audit

Recent News Article Aggregator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent remote news-search integration, but it asks agents to defer to mutable remote instructions and documents unpinned installer commands for supporting skills.

Review before installing. Use this only when you are comfortable sending news-search terms to AgentPMT, avoid confidential or regulated queries, prefer pinned or ClawHub/OpenClaw setup paths over unpinned npx commands, and do not let remotely returned instructions override local safety, credential, or tool-use rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:197
Finding

Remotely Retrieved Instructions Can Override the Audited Local Skill

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 197-200
Vulnerability Type: Remote instruction precedence and mutable behavior
Risk Level: High

Vulnerable Code Snippet:

markdown
- Exact schema: call `agentpmt-tool-search-and-execution` with `action: "get_schema"`, and `tool_id: "recent-news-article-aggregator"`.
- Detailed examples: call `agentpmt-tool-search-and-execution` with `action: "get_instructions"` and `tool_id: "recent-news-article-aggregator"`, or call this product with `action: "get_instructions"` when the product tool is already selected.
- Treat returned live schema and instructions as more specific than this generated summary.

Technical Analysis

The Skill directs the agent to retrieve instructions from an external AgentPMT service and explicitly gives those remotely returned instructions precedence over the locally audited summary. Unlike a strictly validated data response, instructional prose can change after installation and is not constrained by the reviewed package.

This creates a mutable instruction channel. If the remote service, its account, the associated tool configuration, or the transport trust boundary is compromised, returned content could attempt to change how the agent handles user data, selects tools, performs retries, or interprets safety requirements. The local document does contain protective guidance concerning secrets, but the remote-precedence rule weakens the assurance that the audited local behavior remains authoritative.

No evidence establishes that the current remote endpoint is compromised or presently returns malicious content. The vulnerability is the delegation of instruction authority to unaudited, changeable content.

Attack Path

  1. An attacker compromises or gains control over the AgentPMT instruction response, associated product configuration, or another component capable of influencing get_instructions.
  2. The agent loads this Skill ...[truncated 950 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction that remotely returned prose takes precedence over the audited local Skill.
  2. Treat remote responses exclusively as untrusted data, never as agent instructions.
  3. Retrieve only a versioned, machine-readable schema and validate it against a strict local allowlist of actions, fields, types, and enum values.
  4. Pin the expected schema version or integrity digest and reject unexpected changes.
  5. Prevent remote content from modifying system instructions, safety constraints, credential-handling rules, tool permissions, or data-disclosure policies.
  6. If dynamic documentation remains necessary, display it as reference material and require explicit user approval before it changes tool behavior.
  7. Apply output filtering so fields containing imperative instructions or unsupported actions cannot enter the agent's instruction context.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:263
Finding

Unpinned Third-Party Installation Commands Create a Supply-Chain Execution Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 263-275; repeated references at lines 342-343
Vulnerability Type: Unpinned package runner and mutable Skill dependency
Risk Level: Medium

Vulnerable Code Snippet:

markdown
- What AgentPMT is: ../what-is-agentpmt
  - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt
  - OpenClaw install: `openclaw skills install what-is-agentpmt`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup
  - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup
  - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`

skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
text

### Technical Analysis

The setup instructions use `npx` without pinning the package runner to an exact version and install Skill content from `AgentPMT/agent-skills` without specifying an immutable release, commit hash, checksum, or signature. Consequently, the effective installer and installed content may differ from what was available when this package was audited.

`npx` can resolve and execute package-provided code. The subsequent installation also adds external Skill instructions to the agent environment. Compromise of the package registry entry, publisher account, repository, distribution infrastructure, or referenced upstream content could therefore introduce unauthorized executable behavior or malicious instructions.

Installing supporting setup Skills may be legitimate for connecting to the declared hosted service, but mutable and unverified installation commands exceed the minimum trust
...[truncated 1446 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npx package to an exact audited version rather than allowing automatic resolution of the latest release.
  2. Pin AgentPMT/agent-skills to an immutable commit hash or cryptographically signed release.
  3. Publish and verify checksums or signatures for all downloaded Skill content.
  4. Prefer a package manager mode that refuses implicit package downloads and validates a committed lockfile.
  5. Review installed Skills before activation and prevent installation from automatically granting tool or credential access.
  6. Run installation in a sandbox or least-privileged environment without access to unrelated credentials or sensitive files.
  7. Remove duplicate installation instructions and provide a single verified installation path with explicit provenance and integrity checks.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The listed 'Search and activation keywords' include broad phrases such as 'access recent news for up to date content generation' and 'aggregate, search, topic, news type,' which overlap with common task descriptions rather than narrowly identifying this specific skill. This can cause unintended invocation because the file does not provide clear exclusion conditions or negative examples to distinguish when this skill should not activate.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
81% confidence
Finding

The skill is explicitly designed to send user-supplied search terms and request metadata to external AgentPMT endpoints, which creates a real data-transmission boundary. In this context the risk is contextual rather than overtly malicious: if agents pass sensitive prompts, investment intent, or internal research terms, that data can leave the local environment and be exposed to third-party service logging or retention.

Content

Scanner excerpt · SKILL.md (reported line 345)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/recent-news-article-aggregator
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
81% confidence
Finding

This line references the REST invoke endpoint used to transmit requests off-platform, confirming the skill's reliance on remote service calls. The danger is elevated by the skill's financial-news use cases, where user prompts may contain market-sensitive research goals or proprietary strategy context that should not be broadly disclosed to an external provider.

Content

Scanner excerpt · SKILL.md (reported line 346)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/recent-news-article-aggregator
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file states that a bare search returns general US English news by default, and later repeats that default behavior returns US English news across all categories. This establishes a locale/language default that may steer output to a specific region and language without first confirming the user's preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The schema states that the language parameter defaults to en, which can create a language-policy issue by steering outputs toward English without explicit user choice. The file does not indicate that users are offered a language/locale choice before this default is applied.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The generated schema again sets the language default to en, reinforcing an English-first behavior with no documented user opt-in or locale-selection policy. Under the natural-language policy rule, forcing a specific language by default can be a violation unless choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.