Back to skill

Security audit

Zip Unzip File Compression 100mb

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real remote compression tool, but it sends archive contents to AgentPMT cloud storage and relies on mutable remote instructions and unpinned setup installs that users should review carefully.

Install only if you are comfortable sending archive contents and extracted files to AgentPMT cloud storage and receiving signed URLs. Avoid confidential, regulated, or customer-sensitive archives unless your organization approves that storage model. Prefer pinned or reviewed setup packages over the documented unpinned npx commands, and do not let live remote instructions expand the task, data sent, destinations, credentials requested, or security rules without explicit user approval.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:205
Finding

Mutable Remote Instructions Can Override the Audited Skill Definition

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:274
Finding

Unpinned Runtime Installation of Third-Party Skills

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The early description emphasizes compression behavior but does not prominently disclose that decompressed and compressed outputs are uploaded to cloud storage and exposed through signed URLs. That omission can mislead users or agents into sending sensitive files under the assumption of local-only processing, increasing the risk of unintended external disclosure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation keywords include broad generic terms such as compress and archive format, making accidental or overly eager invocation more likely. In this skill's context, unintended activation is meaningful because the tool uploads file contents to remote cloud storage, so a routing mistake can cause unplanned data disclosure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill recommends installing dependencies via unpinned npx skills ..., which can fetch whatever package/version is current at execution time. That creates a supply-chain risk: a compromised upstream package, typosquatted dependency, or breaking update could execute attacker-controlled code in the user's environment during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This line instructs use of npx skills without a pinned version, allowing dynamic retrieval of code from the package registry at runtime. If the package or one of its transitive dependencies is compromised, an agent or user following the skill could execute untrusted code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

An unversioned npx installation command is a real supply-chain exposure because it resolves the latest package state at the time of use. That undermines reproducibility and lets an upstream compromise turn documentation into a code-execution vector.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The install script again relies on unpinned npx skills, exposing consumers to registry-side package substitution or malicious updates. Because these are copy-pastable setup instructions, they directly increase the chance of arbitrary code execution on the client side.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This is the same supply-chain pattern: runtime resolution of an unpinned package through npx. A compromised or unexpected package version could execute code with the privileges of the user or automation environment running the install command.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The reference includes another unpinned npx skills install path, so the skill repeatedly normalizes execution of mutable external code. Repetition across setup guidance increases exposure because multiple workflow entry points lead to the same supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Like the other npx skills references, this command allows retrieval and execution of the latest registry content rather than a known-safe version. In automation contexts, that can become a remote code execution path through dependency compromise.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill explicitly directs data and tool invocations to external AgentPMT endpoints, which constitutes real external transmission. In context this is expected product behavior rather than malicious exfiltration, but it still creates a confidentiality boundary: any provided archive content, metadata, and resulting files leave the local environment and are stored/retrieved through third-party infrastructure.

Content

Scanner excerpt · SKILL.md (reported line 350)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/zip-unzip-file-compression-100mb
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This REST endpoint is another documented path for sending requests and file-related content to a remote service, so the external-transmission finding is valid. The surrounding skill context makes this more dangerous than a generic API reference because the tool processes potentially sensitive archives and returns cloud-hosted signed URLs, extending data exposure beyond the agent runtime.

Content

Scanner excerpt · SKILL.md (reported line 351)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/zip-unzip-file-compression-100mb
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The schema states that all extracted files are uploaded to cloud storage, but this sensitive data handling is only embedded in the action description rather than presented as a prominent user warning or consent checkpoint. Users may provide confidential archives expecting local extraction, causing unintended third-party storage of extracted contents and increasing privacy, compliance, and data exposure risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.