Back to skill

Security audit

Synthetic Data Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed remote synthetic-data generator, with manageable setup and auto-selection caveats but no evidence of hidden or destructive behavior.

Install this only if you intend to use AgentPMT's hosted synthetic-data service. Prefer OpenClaw or pinned/verified setup paths over unpinned npx commands, and avoid sending real secrets, wallet material, payment headers, or production personal data in prompts or tool inputs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:353
Finding

Unpinned Third-Party Installer and Skill Retrieval

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 353–354
Vulnerability Type: Unpinned remote supply-chain dependency
Risk Level: Medium

Vulnerable Code

bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup

Technical Analysis

The Skill instructs users or agents to invoke an npm-delivered CLI through npx and install additional Skills from the mutable AgentPMT/agent-skills source. Neither the CLI nor the retrieved Skill content is pinned to a reviewed package version, commit hash, checksum, or cryptographic signature.

Consequently, the code and instructions executed or installed at setup time may differ from the content that was originally audited. This creates a supply-chain trust boundary: compromise of the npm package, its transitive dependencies, the remote repository, or its publisher account could result in modified code or malicious Skill instructions being delivered to users.

The remote installation is related to configuring the declared hosted service, but executing mutable third-party content without integrity controls exceeds the minimum privilege necessary. A safer setup can use pinned, independently verified artifacts.

Attack Path

  1. An attacker compromises the skills npm package, one of its dependencies, the referenced remote repository, or a relevant publisher account.
  2. The attacker publishes or introduces altered installer code or malicious Skill content.
  3. A user follows the documented setup procedure and executes one of the unpinned npx skills add commands.
  4. npx resolves the current package version, and the installer retrieves mutable content from the remote source.
  5. The compromised component executes with the invoking user's privileges or installs malicious instructions that affect later agent sessions.

This path depends on an upstream supply-chain compromise; the audited project itself c ...[truncated 809 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the skills CLI to a reviewed exact version instead of allowing npx to resolve the latest release.
  2. Pin AgentPMT/agent-skills to an immutable commit hash or signed release tag.
  3. Publish and verify cryptographic checksums or signatures for all downloaded artifacts before installation.
  4. Use a lockfile and integrity metadata for npm dependencies, including transitive dependencies.
  5. Avoid automatic execution of remotely retrieved content; download, inspect, verify, and then install it as separate steps.
  6. Run the installer in a sandbox or least-privileged environment without access to unrelated credentials or sensitive files.
  7. Document the expected artifact digest and provide a procedure for validating publisher signatures and repository ownership.
  8. Review the two setup Skills independently before enabling them in production agent environments.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation keywords include very broad phrases like 'generate', 'data type', and 'count', which can cause the skill to match unrelated user intents. In an agent ecosystem with tool auto-selection, overbroad triggers can lead to unintended remote tool invocation, unnecessary data transmission, and surprising behavior outside the user’s intent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 452)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/synthetic-data-generator
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 453)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/synthetic-data-generator
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file documents synthetic generation of financial data as well as edge-case data containing injection patterns for security testing. Under the markdown warning rule, potentially sensitive or system-impacting behaviors should include a clear warning, but no cautionary note is provided here about safe handling, test-only use, or avoiding production misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file specifies a default locale of en_US rather than requiring an explicit user choice or presenting locale selection neutrally. The policy prohibits forcing a specific language or locale unless the user opts in or the constraint is clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.