T08 · Insecure Dependencies
- Location
SKILL.md:129- Finding
Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This read-only AgentPMT audit-log skill is coherent with its stated purpose, but users should be careful because it can expose sensitive account history and its optional setup docs include unpinned npx installs.
Install this only if you want an agent to read AgentPMT account audit history. Use the narrowest scope available, avoid all_authorized_agent_groups unless needed, and prefer reviewed OpenClaw/ClawHub setup paths or pinned versions instead of copy-pasting unpinned npx commands. Do not include secrets, private keys, mnemonics, signatures, or payment headers in prompts or logs.
SKILL.md:129Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk
The activation keywords include broad natural-language phrases such as summarization and review requests that could plausibly appear in ordinary conversation. In an agentic environment, that can cause unintended skill invocation and unnecessary transmission of chat history, tool-call metadata, or workflow information to the external AgentPMT service.
The skill instructs users to install supporting skills via npx skills ... without pinning an exact package version or immutable source reference. This creates a supply-chain risk: a future compromised or breaking package release could be fetched and executed at install time, especially because npx may download code on demand.
This line again recommends an unpinned npx skills installation path for a dependency skill. Because execution depends on whatever package version resolves at runtime, an attacker controlling the package or distribution path could deliver malicious code during installation.
The example install script uses npx without a fixed version, which exposes consumers to remote code execution risk through package substitution, typosquatting, or malicious updates. Because this is presented as copy-paste setup guidance, the likelihood of direct operator execution is higher than a passive reference.
This second line in the install script repeats the same floating npx dependency installation pattern. Repetition increases exposure because users are encouraged to execute multiple network-fetched commands before using the skill.
The reference section includes another unpinned npx skills command, which continues the same supply-chain exposure. Even though it appears in documentation rather than executable code, the skill is explicitly instructing operators how to install supporting components, so the risk is operationally real.
This line repeats an unversioned npx skills installation command for another support skill. If the package publisher account or upstream package is compromised, users following the documentation could execute attacker-controlled code.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/agentpmt-audit-logs
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/agentpmt-audit-logs
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
This markdown schema documents an action that fetches a chat transcript page and correlated tool calls, which can expose prior user conversation content and activity metadata. The file does not include any warning or disclosure about privacy-sensitive access to historical chat data, despite SQP-2 applying to markdown files that describe behaviors affecting user data or privacy.
The schema states that the all_authorized_agent_groups scope reads every agent group the user can access, which broadens the data returned beyond the current workflow context. The markdown provides no caution that selecting this scope may expose more user, workflow, or audit data than expected, creating a missing disclosure for privacy-impacting behavior.
The manifest describes this skill as an audit-log reader focused on past chat sessions, transcripts, and tool-call history. This schema additionally exposes actions to fetch workflow run results and scheduled workflow details, which are distinct operational resources not mentioned in the manifest description and therefore broaden the documented behavior beyond chat/tool-call audit logs.
The when-to-use guidance is broad and overlaps with common agent tasks like summarizing past activity or reviewing conversations. While not a direct exploit primitive, ambiguous boundaries increase the chance of accidental invocation of an external audit-log skill in contexts where the user did not explicitly request it.
The manifest positions the skill around account activity audit logs, especially chat sessions and tool calls. The documented get_instructions action explicitly says it explains reading workflow runs and scheduled workflows, indicating a broader product scope than the manifest communicates.
No suspicious patterns detected.