Back to skill

Security audit

PMP-Agentclaw

Security checks for vulnerabilities and agentic risk

Overview

The skill’s project-management behavior is mostly coherent, but its documented runtime and install paths can execute mutable remote npm or GitHub code with user-level access.

Review before installing. Prefer a pinned, reviewed release or local audited executable; avoid copy-pasting the unpinned npx commands against sensitive project directories, and use npm ci from a verified commit if building locally. The reviewed code itself did not show exfiltration, destructive behavior, credential access, or persistence beyond normal skill installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:137
Finding

Unpinned npx Command Can Retrieve and Execute Mutable Registry Code

Content
View full analysis
Remediation
View remediation
``` Alternatively, prohibit network installation during execution: ```bash npx --no-install pmp-agentclaw health-check ``` Additional hardening measures: 1. Do not permit the health check to install packages implicitly. 2. If registry retrieval is unavoidable, pin an exact reviewed version rather than using the latest available release. 3. Verify package integrity and provenance before execution. 4. Document that execution must fail closed when the trusted local package is unavailable. 5. Run the command with minimal filesystem, environment-variable, and network privileges. ]]>

T08 · Insecure Dependencies

Warning
Location
INSTALL.md:13
Finding

Manual Installation Executes Code from an Unpinned Repository Branch

Content
View full analysis
Remediation
View remediation
npm ci npm run build ``` Additional hardening measures: 1. Publish signed release tags and document the exact approved tag or commit. 2. Provide SHA-256 checksums or signed provenance for release archives. 3. Replace `npm install` with `npm ci` so dependency installation follows the lockfile exactly. 4. Review package lifecycle scripts before installation. 5. Consider initially installing with lifecycle scripts disabled: ```bash npm ci --ignore-scripts ``` Then run only the explicitly reviewed build command. 6. Avoid cloning directly into a live Skill directory before verification; download and verify the release in a staging directory first. 7. Update the duplicate mutable clone instruction in `README.md` to use the same pinned-release procedure. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (39)

Known Vulnerable Dependency: handlebars==4.7.8 — 8 advisory(ies): CVE-2026-33916 (Handlebars.js has Prototype Pollution Leading to XSS through Partial Template In); CVE-2026-33937 (Handlebars.js has JavaScript Injection via AST Type Confusion); CVE-2026-33938 (Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @part) +5 more

Critical
Category
Supply Chain
Confidence
95% confidence
Finding

handlebars 4.7.8 is affected by multiple severe issues including prototype pollution and potential code or script injection depending on template handling. Even though it is only in the development dependency tree here through ts-jest, template-compilation in build/test tooling can become dangerous if any attacker-controlled templates or AST-like inputs are processed on developer machines or CI runners.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a comprehensive AI project management assistant covering many PM disciplines and methodologies. The provided code chunk instead implements a narrow command-line utility that accepts a project directory, invokes a health check function, outputs the result in JSON or Markdown, and sets the process exit code based on health status. This is materially different in primary purpose and capabilities from the declared description. While a health check could loosely relate to project monitoring, the implemented behavior is far narrower and does not substantiate the broad project management capabilities claimed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description promises a comprehensive AI project management assistant supporting many PM functions across waterfall, agile, and hybrid methods. The supplied code chunk only implements a CLI entrypoint that recognizes a few commands and prints help or a 'Run:' alias string. Its functional scope is much narrower: EVM calculation, basic risk scoring, velocity calculation, and a health-check command. There is no evidence here of AI assistant behavior or of support for planning, schedule tracking, WBS generation, status reports, RACI assignment, or broad project management workflows. While some listed functions loosely align with the description (earned value, risk, sprint velocity), the actual code's primary purpose and implemented capability set are materially narrower than declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a comprehensive AI project management assistant capable of many planning and management functions. The supplied code chunk instead implements a narrow CLI entrypoint for running a health check against a project directory and outputting the result in JSON or Markdown. This is a materially different primary purpose from the declared broad PM assistant behavior. While 'project health' could loosely relate to project management, the code shown does not support the stated capabilities such as planning, tracking schedules, managing risks, calculating earned value, running sprints, creating WBS, generating status reports, or assigning RACI responsibilities. The command-line trigger and directory-based health check behavior are also not reflected in the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises a comprehensive AI project management assistant covering many PM activities and methodologies. The supplied code only implements a narrow CLI dispatcher for four utility-style commands related to EVM, risk scoring, velocity, and health checks, and it appears to print the alias to run rather than execute substantive assistant logic itself. While these functions are within the project-management domain, the actual behavior is materially narrower than the declared purpose, so the description does not accurately represent what this code chunk does.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==1.1.12 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
97% confidence
Finding

brace-expansion 1.1.12 is present multiple times in the dependency tree and is flagged for denial-of-service issues involving pathological brace patterns that can trigger excessive CPU or memory use. Although this appears to be in dev tooling, any workflow that feeds attacker-controlled glob or pattern input into affected tooling could hang local or CI processes.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: minimatch==3.1.2 — 3 advisory(ies): CVE-2026-27904 (minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regu); CVE-2026-26996 (minimatch has a ReDoS via repeated wildcards with non-matching literal in patter); CVE-2026-27903 (minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adja)

High
Category
Supply Chain
Confidence
97% confidence
Finding

minimatch 3.1.2 is affected by multiple ReDoS/backtracking issues that can be triggered with crafted glob patterns. In this project it is transitively used by development tools, making the main risk CI or developer workstation denial of service rather than direct runtime compromise.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==3.14.2 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
93% confidence
Finding

js-yaml 3.14.2 is flagged for CPU consumption issues involving crafted merge structures and omap parsing. Even though it is a transitive dev dependency here, parsing attacker-controlled YAML in build, test, or config-processing paths could stall automation or consume excessive resources.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==2.0.2 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
97% confidence
Finding

brace-expansion 2.0.2 has the same class of expansion-based DoS issues as the 1.x branch, allowing crafted patterns to trigger excessive processing or memory exhaustion. Because it sits in the tooling chain, the most likely consequence is denial of service in local development or CI jobs rather than production compromise.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: browserslist==4.28.1 — 2 advisory(ies): CVE-2026-73088 (Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.); CVE-2026-73089 (Browserslist: Unbounded memory growth (no cache eviction) via distinct query res)

High
Category
Supply Chain
Confidence
90% confidence
Finding

browserslist 4.28.1 is reported with crash/prototype-write and unbounded memory growth issues when handling untrusted stats or distinct query results. In this repository it is a tooling dependency, but if CI/build processes ingest attacker-controlled browserslist config or stats data, builds could be crashed or destabilized.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: flatted==3.3.3 — 2 advisory(ies): CVE-2026-32141 (flatted vulnerable to unbounded recursion DoS in parse() revive phase); CVE-2026-33228 (Prototype Pollution via parse() in NodeJS flatted)

High
Category
Supply Chain
Confidence
92% confidence
Finding

flatted 3.3.3 is flagged for unbounded recursion DoS and prototype pollution during parse reviver handling. While it is a transitive development dependency here, any tooling path that parses attacker-controlled flatted payloads could crash or taint object prototypes in the Node process.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==4.1.1 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
93% confidence
Finding

js-yaml 4.1.1 is also present and carries high-severity CPU exhaustion issues related to crafted YAML merge content and omap handling. As with the 3.x instance, the primary risk in this project is denial of service in tooling or CI if untrusted YAML is parsed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The installation guide recommends running npx pmp-agentclaw without pinning a specific version, which causes npm to resolve and execute whatever package version is current at invocation time. If the package is ever compromised, typosquatted, republished with malicious content, or a malicious dependency is introduced, users may execute unreviewed code during a project-management workflow where local file and environment access are common.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to execute npx pmp-agentclaw without pinning a specific package version. npx may fetch and run the latest published package at execution time, which creates a supply-chain risk if a malicious or compromised update is published under that name. Because this is installation/verification guidance in a skill README, it can directly influence users into executing unreviewed remote code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This CLI example uses npx pmp-agentclaw without a version pin, so running the documented command can download and execute whatever version is current in the registry. That exposes users to package takeover, maintainer compromise, or malicious update scenarios typical of npm supply-chain attacks. In an agent skill context, README commands are especially risky because users often copy-paste them verbatim.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The documented npx pmp-agentclaw score-risks ... invocation is unpinned and therefore subject to executing newly published code from the npm registry at runtime. If the package is hijacked or updated maliciously, users could run attacker-controlled code on their systems. The project management theme of the skill does not reduce this danger because the risk comes from package execution, not business logic.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This example again relies on npx pmp-agentclaw without constraining the version, which is a classic supply-chain exposure. Users following the README may unknowingly execute a different package version in the future than the author intended, including a compromised release. Since the command appears in normal usage examples, the likelihood of copy-paste execution is nontrivial.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The health-check ./my-project example is also unpinned, but it is somewhat more dangerous because it suggests running registry-fetched code against a local project path, increasing the potential value of a compromise. A malicious package version could inspect, exfiltrate, or modify files in the specified workspace. In the context of a developer-facing skill, commands that operate on local directories amplify the supply-chain risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L004 says to use the skill for 'planning, tracking, and managing projects' and 'any project management task,' which is extremely broad and lacks clear trigger boundaries. Because it provides no negative examples or narrower activation constraints, the skill may be invoked for common workplace language that only loosely relates to project management.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The instruction to run npx pmp-agentclaw health-check invokes a package by name without pinning a specific version or integrity, which can fetch whatever version is currently published. That creates a supply-chain risk: a compromised, typosquatted, or newly malicious package version could execute arbitrary code in the user's environment when the skill is followed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The guide instructs users to run npx pmp-agentclaw without pinning an exact version, which can cause execution of whatever package version is currently resolved from the registry. If the package is later compromised, typo-squatted, or updated with malicious code, users following the documentation could execute unreviewed code on their system.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file header and usage text present this module as the "CLI Main Entry" for commands like calc-evm, score-risks, and health-check, implying it dispatches to those implementations. However, after resolving the command, the code at L66-L69 merely formats and prints Run: ... rather than invoking the target script, so the documented behavior contradicts the actual behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest describes a project management assistant for planning, tracking, and managing projects, but these lines explicitly direct the skill to assign work across 'multiple AI agents.' Coordinating other agents is a distinct orchestration capability that is not clearly justified or declared by the manifest text.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.