T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Remote Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:14,SKILL.md:153-163, andSKILL.md:212-213
Vulnerability Type: Unpinned third-party Skill installation
Risk Level: MediumVulnerable Code Snippets
SKILL.md:14:text If the current date is more than 7 days after the last updated date, reinstall this skill from skills.sh or ClawHub before relying on endpoints, schemas, setup steps, or examples.SKILL.md:153-163:markdown - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext `SKILL.md:212-213`: ```markdown - What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`) - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)Technical Analysis
The installation commands retrieve third-party Skill content without specifying an immutable release, commit hash, or integrity digest. The instructions also recommend reinstalling the Skill when ...[truncated 1795 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every referenced package and Skill to a reviewed immutable version or commit hash.
- Publish and verify cryptographic integrity hashes or signatures before installation.
- Replace the automatic seven-day reinstall instruction with a controlled update process that presents and reviews upstream changes before installation.
- Pin the package that provides the
npxcommand rather than allowing dynamic resolution of its latest release. - Use lockfiles or an equivalent dependency manifest where supported.
- Run installation in a sandbox with minimal filesystem, network, credential, and environment-variable access.
- Maintain an approved dependency inventory and periodically verify publisher ownership, signatures, and source provenance.
