Back to skill

Security audit

Secure Python Code Sandbox

Security checks for vulnerabilities and agentic risk

Overview

This skill is for a real remote Python sandbox, but it asks agents to trust live remote instructions and uses mutable setup commands, so users should review it carefully before use.

Install or use this only if you are comfortable sending the submitted Python code and any embedded data to AgentPMT. Do not include secrets, proprietary source, personal data, payment credentials, wallet material, or internal API tokens unless you have explicit approval. Prefer pinned or ClawHub-reviewed setup paths, and treat any live instructions returned by the service as reference data that cannot override local user, privacy, or safety requirements.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:115
Finding

Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 115-125
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

markdown
- What AgentPMT is: ../what-is-agentpmt
  - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt
  - OpenClaw install: `openclaw skills install what-is-agentpmt`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup
  - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup
  - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`

skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
text

### Technical Analysis

The Skill directs users or agents to execute an unpinned package through `npx` and install skills from a mutable repository reference. It does not specify an exact `skills` package version, an immutable AgentPMT repository commit, or an integrity checksum.

Consequently, the components executed or installed during setup can differ from those reviewed in this project. The additional account-setup skill is relevant to accessing the hosted service, but importing mutable third-party content expands the trusted computing base and exceeds the minimum-risk approach to dependency installation.

No evidence shows that the current dependency is malicious. The vulnerability is the absence of version and integrity controls, which exposes installation to future package compromise, repository compromise, maintainer-account takeover, or malicious updates.

### Attack Path

1. The referenced setup skills are absent from the local environment.
2. An agen
...[truncated 1176 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the skills npm package to an exact reviewed version rather than allowing npx to resolve a mutable release.
  2. Pin the AgentPMT skill repository to an immutable commit hash or cryptographically signed release.
  3. Publish and verify SHA-256 checksums or signatures for all installed skill artifacts.
  4. Require explicit user confirmation before downloading or installing additional skills.
  5. Avoid automatic installation during ordinary invocation; provide reviewed, bundled setup documentation where practical.
  6. Run installation in a restricted environment without access to unrelated credentials or sensitive files.
  7. Re-audit dependency updates before changing pinned versions.

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:48
Finding

Externally Mutable Instructions Are Given Precedence Over Audited Local Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 48-50
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Medium

Vulnerable Code

markdown
- Exact schema: call `agentpmt-tool-search-and-execution` with `action: "get_schema"`, and `tool_id: "secure-python-code-sandbox"`.
- Detailed examples: call `agentpmt-tool-search-and-execution` with `action: "get_instructions"` and `tool_id: "secure-python-code-sandbox"`, or call this product with `action: "get_instructions"` when the product tool is already selected.
- Treat returned live schema and instructions as more specific than this generated summary.

The remote-instruction behavior is invoked again during error handling at line 165:

markdown
- If validation fails or the response shape is unclear, call `get_schema` or `get_instructions` before retrying.

Technical Analysis

The local Skill instructs the agent to retrieve operational instructions from an external AgentPMT service and treat those instructions as more specific than the locally audited documentation. The remote content can change independently after publication and review of this project.

This creates an instruction-injection boundary: externally supplied text is not merely treated as response data but can influence how the agent operates the tool. The Skill does not explicitly state that remotely returned instructions are untrusted, constrain them to a fixed schema, or prohibit them from overriding local security and privacy requirements.

There is no evidence that the current AgentPMT responses are malicious. The risk arises because compromise of the service, response path, or associated account could allow mutable external instructions to steer the agent beyond the behavior reviewed in SKILL.md.

Attack Path

  1. The agent prepares a production integration, encounters an unclear response, or experiences validation failure.
  2. Following SKILL.md ...[truncated 1291 chars]
Remediation
View remediation

Remediation Suggestions

  1. Treat all remotely returned schemas, examples, and instructions as untrusted data rather than authoritative agent instructions.
  2. State explicitly that remote content cannot override system, developer, user, security, privacy, or locally packaged Skill constraints.
  3. Validate responses against a locally pinned schema and an explicit allowlist containing only the required invoke, get_schema, and narrowly defined support operations.
  4. Pin remote schema and instruction versions or verify signed responses before use.
  5. Require user confirmation when remote content requests new capabilities, additional data, new endpoints, or actions not declared by the local Skill.
  6. Parse schema responses structurally and reject instruction-like text in fields expected to contain data.
  7. Apply strict data minimization so source code containing credentials, personal information, or proprietary data is not submitted without informed user approval.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill promotes 'safe' execution but does not prominently warn that supplied code will be transmitted to and executed on a remote hosted service. That omission can mislead users or upstream agents into sending proprietary code, secrets, personal data, or internal logic off-platform under the assumption of local or purely isolated execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation keywords are broad terms like dynamic code execution, data manipulation, and API integration that overlap with many normal developer requests. In an agent ecosystem, this can cause the skill to be selected in contexts where users did not explicitly intend remote code execution, increasing the risk that sensitive data or unsafe code is sent to a hosted sandbox.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 177)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/secure-python-code-sandbox
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/secure-python-code-sandbox
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema explicitly advertises execution of arbitrary Python code, including dynamic API calls via preinstalled libraries like requests, but provides no safety guidance about secrets exposure, data exfiltration, network access, abuse of remote services, or harmful side effects. In an agent-integrated context, this is dangerous because it can encourage unsafe use of untrusted code and sensitive inputs under the misleading framing of being 'secure' without clearly stating the sandbox's limits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.