T08 · Insecure Dependencies
- Location
SKILL.md:63- Finding
Unpinned Third-Party npm Package Installation and Execution with Bearer-Token Access
- Content
View full analysis
", "AGENTPMT_MCP_ENDPOINT": "https://api.agentpmt.com/mcp/" } } } } ``` ### Technical Analysis The documented installation command does not pin `@agentpmt/mcp-router` to a reviewed version. The alternative configuration explicitly requests the mutable `@latest` release through `npx`. Consequently, the code ultimately downloaded and executed can change after the Skill has been reviewed. The global installation path increases the potential system-wide impact. The executed router is also given direct access to `AGENTPMT_BEARER_TOKEN`. If the npm package, maintainer account, publication process, or a future package release were compromised, package lifecycle scripts or router code could execute arbitrary commands and read or exfiltrate the token. This finding does not establish that the current package is malicious. It identifies an avoidable software-supply-chain trust boundary. Sending the token to the declared AgentPMT API is necessary for the Skill's authenticated integration, but exposing it to mutable local package code creates additional risk beyond the minimum required for the hosted MCP option. ### Attack Path 1. An attacker compromises the npm package, its maintainer account, or its release pipeline and publishes a malicious version. 2. A user follows the Skill instructions and either globally installs the package without a version constraint or launches `@agentpmt/mcp-router@latest` through `npx`. 3. npm retrieves and executes the attacker-controlled release ...[truncated 1224 chars]- Remediation
View remediation
agentpmt-router ``` 2. Publish and verify the expected npm integrity hash or package provenance before execution. 3. Prefer a project-local installation governed by a committed lockfile rather than `npm install -g`. 4. Use `npm ci` with a reviewed lockfile where a persistent local installation is required. 5. Avoid running npm, package lifecycle scripts, or the router with administrator or root privileges. 6. Run the router in a restricted environment with only the network and filesystem permissions necessary for its declared function. 7. Scope the AgentPMT Bearer Token to the smallest possible Agent Group catalog and avoid assigning unrelated tools, workflows, or credentials. 8. Document token rotation and revocation procedures. Rotate the token immediately if package compromise or unexpected execution is suspected. 9. Prefer the hosted MCP endpoint when supported, because it avoids executing an additional mutable npm router on the user's machine. 10. Establish a controlled package-update process in which new versions are reviewed and tested before the pinned version is changed. ]]>
