T01 · Skill Instruction Hijacking
- Location
SKILL.md:205- Finding
Mutable Remote Instructions Can Override the Audited Skill Definition
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a real remote compression tool, but it sends archive contents to AgentPMT cloud storage and relies on mutable remote instructions and unpinned setup installs that users should review carefully.
Install only if you are comfortable sending archive contents and extracted files to AgentPMT cloud storage and receiving signed URLs. Avoid confidential, regulated, or customer-sensitive archives unless your organization approves that storage model. Prefer pinned or reviewed setup packages over the documented unpinned npx commands, and do not let live remote instructions expand the task, data sent, destinations, credentials requested, or security rules without explicit user approval.
SKILL.md:205Mutable Remote Instructions Can Override the Audited Skill Definition
SKILL.md:274Unpinned Runtime Installation of Third-Party Skills
The early description emphasizes compression behavior but does not prominently disclose that decompressed and compressed outputs are uploaded to cloud storage and exposed through signed URLs. That omission can mislead users or agents into sending sensitive files under the assumption of local-only processing, increasing the risk of unintended external disclosure.
The activation keywords include broad generic terms such as compress and archive format, making accidental or overly eager invocation more likely. In this skill's context, unintended activation is meaningful because the tool uploads file contents to remote cloud storage, so a routing mistake can cause unplanned data disclosure.
The skill recommends installing dependencies via unpinned npx skills ..., which can fetch whatever package/version is current at execution time. That creates a supply-chain risk: a compromised upstream package, typosquatted dependency, or breaking update could execute attacker-controlled code in the user's environment during installation.
This line instructs use of npx skills without a pinned version, allowing dynamic retrieval of code from the package registry at runtime. If the package or one of its transitive dependencies is compromised, an agent or user following the skill could execute untrusted code.
An unversioned npx installation command is a real supply-chain exposure because it resolves the latest package state at the time of use. That undermines reproducibility and lets an upstream compromise turn documentation into a code-execution vector.
The install script again relies on unpinned npx skills, exposing consumers to registry-side package substitution or malicious updates. Because these are copy-pastable setup instructions, they directly increase the chance of arbitrary code execution on the client side.
This is the same supply-chain pattern: runtime resolution of an unpinned package through npx. A compromised or unexpected package version could execute code with the privileges of the user or automation environment running the install command.
The reference includes another unpinned npx skills install path, so the skill repeatedly normalizes execution of mutable external code. Repetition across setup guidance increases exposure because multiple workflow entry points lead to the same supply-chain risk.
Like the other npx skills references, this command allows retrieval and execution of the latest registry content rather than a known-safe version. In automation contexts, that can become a remote code execution path through dependency compromise.
The skill explicitly directs data and tool invocations to external AgentPMT endpoints, which constitutes real external transmission. In context this is expected product behavior rather than malicious exfiltration, but it still creates a confidentiality boundary: any provided archive content, metadata, and resulting files leave the local environment and are stored/retrieved through third-party infrastructure.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/zip-unzip-file-compression-100mb
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
This REST endpoint is another documented path for sending requests and file-related content to a remote service, so the external-transmission finding is valid. The surrounding skill context makes this more dangerous than a generic API reference because the tool processes potentially sensitive archives and returns cloud-hosted signed URLs, extending data exposure beyond the agent runtime.
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/zip-unzip-file-compression-100mb
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The schema states that all extracted files are uploaded to cloud storage, but this sensitive data handling is only embedded in the action description rather than presented as a prominent user warning or consent checkpoint. Users may provide confidential archives expecting local extraction, causing unintended third-party storage of extracted contents and increasing privacy, compliance, and data exposure risk.
No suspicious patterns detected.