Back to skill

Security audit

Webhook Http Request

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate HTTP request skill, but it needs Review because it can send data and credentials to arbitrary endpoints and includes weakly scoped private-network and live-instruction behavior.

Install only if you need a generic AgentPMT HTTP client and trust AgentPMT to process your requests. Use least-privilege tokens, verify every destination before sending secrets or payloads, avoid allow_private unless you explicitly need private-network access, and require confirmation before PUT, PATCH, or DELETE calls. Prefer pinned, reviewed setup instructions for related skills.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:156
Finding

Private-Network Access Override Creates an SSRF Primitive

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:156; supporting schema at schema.md:58-63
Vulnerability Type: Server-Side Request Forgery through configurable private-network access
Risk Level: High

Vulnerable code snippet:

markdown
- Requests to private or loopback IP addresses are blocked by default. Set `allow_private` to `true` to override.
json
"allow_private": {
  "default": false,
  "description": "Set to true to allow requests to private or loopback IP addresses.",
  "required": false,
  "type": "boolean"
}

Technical Analysis

The Skill is a general-purpose HTTP client and therefore legitimately requires outbound network access. However, ordinary webhook and third-party REST API operations do not require access to private, loopback, link-local, or cloud metadata addresses.

The allow_private option lets an Agent disable the principal SSRF boundary using an ordinary request parameter. The schema does not require user approval, administrative authorization, or an allowlisted destination before enabling this behavior. The reviewed instructions also do not specify protections against DNS rebinding, alternate IP encodings, link-local destinations, cloud metadata services, or redirects from public URLs to private addresses.

Because the tool returns the response body and metadata to the Agent, private-network access can potentially be used for both reconnaissance and data retrieval.

Attack Path

  1. An attacker supplies a prompt, document, API response, or other content that influences the Agent.
  2. The content instructs the Agent to request an attacker-selected private, loopback, link-local, or metadata URL.
  3. The Agent invokes the request action with allow_private: true.
  4. The hosted request service connects to a destination that is inaccessible to the external attacker.
  5. The service returns the status, headers, final URL, and response body to the Agent.

...[truncated 721 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove allow_private from the general request schema.
  • If private access is an essential enterprise feature, place it behind an administrator-controlled policy rather than an Agent-controlled boolean.
  • Require explicit, per-request user approval that displays the resolved destination and explains the risk.
  • Use destination allowlists scoped to the specific integration.
  • Block loopback, private, link-local, multicast, reserved, and cloud metadata ranges for both IPv4 and IPv6.
  • Resolve and validate every destination immediately before connection.
  • Revalidate every redirect target and prohibit redirects from public to non-public addresses.
  • Pin validated DNS results through connection establishment to mitigate DNS rebinding.
  • Normalize and reject alternative IP address representations.
  • Record security events without logging credentials or sensitive response bodies.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:42
Finding

Authentication Secrets Are Passed Through a Hosted Remote Request Service Without Enforced Secret Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:42-45; supporting references at SKILL.md:6,81,93,105,282-286,304-308,323 and schema.md:23-25,69-83
Vulnerability Type: Sensitive credential exposure across a third-party processing boundary
Risk Level: Medium

Vulnerable code snippet:

markdown
- `auth_password` — password for basic auth (required when auth_type is `"basic"`)
- `auth_token` — token for bearer auth (required when auth_type is `"bearer"`)
- `auth_header_name` — custom header name for header auth (required when auth_type is `"header"`)
- `auth_header_value` — custom header value for header auth (required when auth_type is `"header"`)

The Skill also describes its execution model as:

yaml
compatibility: "Agent instructions for AgentPMT-hosted remote tool calls. Follow this skill body for supported account, wallet, and setup routes. No local command runtime is declared."

Its retry guidance states:

markdown
- If `request` fails, preserve the request parameters and retry only after fixing schema, auth, or payment errors.

Technical Analysis

Bearer tokens, passwords, and custom authentication values are accepted as ordinary string parameters and sent through an AgentPMT-hosted request service. This intermediary access may be functionally necessary for authenticated remote requests, but the reviewed schema does not mark these fields as secret, non-loggable, origin-bound, or single-use.

The prose warns against placing account secrets in prompts or logs, but this is not an enforceable schema or runtime control. In addition, preserving request parameters for retries may retain credentials in Agent context, traces, or retry state longer than necessary.

The package does not document credential retention, redaction, access control, encryption guarantees beyond the remote transport assumption, or safeguards preventing credentials intended for one origin from being sent ...[truncated 1385 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace raw credential parameters with opaque secret references resolved only inside the trusted dispatcher.
  • Mark all authentication fields as secret and prohibit their inclusion in prompts, telemetry, error messages, traces, and audit logs.
  • Bind every stored credential to an explicit scheme, host, port, and path policy.
  • Refuse to forward credentials after cross-origin redirects.
  • Require HTTPS whenever authentication material is present.
  • Use short-lived, least-privileged tokens instead of reusable passwords where possible.
  • Redact authentication fields before preserving or retrying request parameters.
  • Obtain explicit user consent before sending credentials through a hosted intermediary.
  • Publish and enforce credential retention, deletion, encryption, and operator-access policies.
  • Add automated tests verifying that secrets never appear in logs, returned errors, or response metadata.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:269
Finding

Setup Instructions Install Unpinned Third-Party Content Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:269-270; additional occurrences at SKILL.md:260,264,331-332
Vulnerability Type: Unpinned third-party dependency and mutable supply-chain source
Risk Level: Medium

Vulnerable code snippet:

bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup

Technical Analysis

The setup procedure invokes npx and installs Skills from AgentPMT/agent-skills without specifying a CLI version, repository commit, release tag, checksum, or signature. Consequently, the content installed when a user follows these instructions can differ from the content available at audit time.

These setup Skills handle account and remote API connectivity, which is a sensitive trust boundary. A compromise of the package distribution path, repository, maintainer account, or mutable default branch could introduce altered instructions or executable behavior that is not present in this two-file project.

The audit found no evidence that the current dependency is malicious. The vulnerability is the absence of reproducible and verifiable dependency pinning.

Attack Path

  1. An attacker compromises a dependency publisher, package distribution account, repository, or referenced mutable branch.
  2. The attacker modifies the setup Skill or the CLI behavior.
  3. A user follows the documented unpinned npx skills add command.
  4. The current attacker-controlled version is downloaded instead of a reviewed immutable version.
  5. The installed component gains the trust associated with account setup and may solicit credentials, change endpoints, or introduce additional behavior.

Impact Assessment

Impact depends on the behavior and permissions of the installed setup components. Because they configure account, MCP, and REST connectivity, compromise could expose account credentials, redirect remote ...[truncated 224 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the npx package or CLI to a reviewed exact version.
  • Pin the Skill repository to an immutable commit hash or signed release.
  • Publish cryptographic checksums and verify them before installation.
  • Use signed provenance metadata and verify the publisher identity.
  • Maintain a lock file or manifest identifying every reviewed dependency version.
  • Avoid automatic installation; display the source, version, permissions, and integrity value for user approval.
  • Vendor small, security-critical setup instructions into the audited package when practical.
  • Re-audit dependencies whenever their pinned versions change.

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:191
Finding

Mutable Remote Instructions Are Given Precedence Over the Audited Skill

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:191-195
Vulnerability Type: Remote instruction precedence and post-review behavior mutation
Risk Level: Medium

Vulnerable code snippet:

markdown
## Live Schema And Examples
Use the compact schema above for ordinary calls. Before a new production integration, or whenever parameters, enum values, nested objects, outputs, or examples are unclear, fetch live details first.

- Exact schema: call `agentpmt-tool-search-and-execution` with `action: "get_schema"`, and `tool_id: "webhook-http-request"`.
- Detailed examples: call `agentpmt-tool-search-and-execution` with `action: "get_instructions"` and `tool_id: "webhook-http-request"`, or call this product with `action: "get_instructions"` when the product tool is already selected.
- Treat returned live schema and instructions as more specific than this generated summary.

Technical Analysis

The Skill tells the Agent to retrieve mutable instructions from a remote service and treat them as more specific than the locally reviewed content. This permits effective behavior to change after package review without a corresponding update to the audited files.

Fetching a live schema can be legitimate for compatibility, but remote prose must not be granted instructional authority. The reviewed Skill does not state that returned content is untrusted data, cannot override safety requirements, cannot request additional secrets, and must remain within a pinned local action schema.

This differs from confirmed remote code execution: no instruction to download and execute program code was found. The issue is remote control over Agent instructions and tool behavior.

Attack Path

  1. The remote instruction service, its account, or its content pipeline is compromised or modified.
  2. The Agent encounters an unclear field or begins a production integration.
  3. Following the local Skill, the Agent calls get_instructions. ...[truncated 842 chars]
Remediation
View remediation

Remediation Suggestions

  • Treat all remotely returned prose as untrusted data, not as Agent instructions.
  • Remove the directive that remote instructions take precedence over the local Skill.
  • Pin live schemas to a version or cryptographic digest reviewed with the package.
  • Validate remote responses against a restrictive local schema before use.
  • Permit remote data to clarify field values only; prohibit it from changing safety rules, destinations, credential handling, or tool permissions.
  • Reject unexpected fields and instruction-like text in schema responses.
  • Require explicit review and a local Skill version update for behavioral changes.
  • Preserve immutable copies of approved schemas for audit and rollback.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (19)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill is explicitly designed to send arbitrary HTTP requests, including authenticated requests and request bodies, yet its primary description lacks a prominent warning that use may transmit secrets or sensitive user data to third-party endpoints. In this context, missing disclosure is dangerous because the tool's normal capability is external data egress, and users or upstream agents may invoke it without appreciating that risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

{ "action": "request", "request_method": "GET", "url": "https://api.example.com/data", "query_params": {"format": "json"} }

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

{ "action": "request", "request_method": "GET", "url": "https://api.example.com/data", "query_params": {"format": "json"} }

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

{ "action": "request", "request_method": "GET", "url": "https://api.example.com/data", "query_params": {"format": "json"} }

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The examples demonstrate bearer auth, basic auth, custom API keys, PUT, and DELETE operations without adjacent cautionary text about secret handling, endpoint trust, or destructive effects. In a skill whose purpose is arbitrary outbound HTTP access, such examples normalize risky actions and can lead agents to repeat them with real credentials or production resources.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This example shows bearer-token transmission to an external endpoint. Although the domain is a placeholder, the example normalizes sending live credentials over arbitrary outbound HTTP and, without adjacent caution text, raises the risk that users or agents will substitute real secrets and exfiltrate them to untrusted services.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
{
  "action": "request",
  "request_method": "GET",
  "url": "https://api.example.com/protected/resource",
  "auth_type": "bearer",
  "auth_token": "eyJhbGciOiJIUzI1NiIs..."
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This example demonstrates basic-auth credential transmission to an external endpoint. In the context of a generic HTTP client skill, examples that include usernames and passwords without strong warning text materially increase the chance of credential disclosure through misuse or overbroad agent activation.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
{
  "action": "request",
  "request_method": "GET",
  "url": "https://api.example.com/account",
  "auth_type": "basic",
  "auth_username": "myuser",
  "auth_password": "mypassword"

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

This example sends a custom API key header to an external service. The main danger is not the placeholder itself but the precedent it sets in a skill already capable of arbitrary outbound requests, especially given the lack of prominent warning about secret exfiltration.

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
{
  "action": "request",
  "request_method": "GET",
  "url": "https://api.example.com/v2/search",
  "auth_type": "header",
  "auth_header_name": "X-API-Key",
  "auth_header_value": "abc123def456"

External Transmission

Medium
Category
Data Exfiltration
Confidence
76% confidence
Finding

The DELETE example illustrates a destructive outbound action to an arbitrary external endpoint without nearby warning or confirmation guidance. In an agent skill with broad HTTP powers, showcasing deletion operations casually increases risk of accidental or unauthorized destructive actions if selected inappropriately.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

{ "action": "request", "request_method": "DELETE", "url": "https://api.example.com/items/42" }

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation keywords include very generic terms such as request and url, which can cause this powerful exfiltration-capable HTTP skill to be selected for ordinary tasks. In agentic environments, overbroad triggering increases the chance of unintended outbound requests, sensitive-data transmission, or destructive API actions without the user explicitly intending to use a webhook tool.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 334)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/webhook-http-request
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 335)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/webhook-http-request
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This schema exposes a highly flexible HTTP request capability, including arbitrary URLs, custom headers, bearer/basic/header authentication, and an option to allow private or loopback targets, but it does not present any user-facing warnings or guardrails about SSRF, credential leakage, or sending secrets to untrusted endpoints. In an agent context, this increases the chance that users or downstream prompts will misuse the action to access internal services or exfiltrate sensitive tokens without understanding the risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.