T08 · Insecure Dependencies
- Location
SKILL.md:504- Finding
Unpinned Remote Package and Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:504-508
Vulnerability Type: Supply-chain risk from mutable, unpinned remote dependencies
Risk Level: MediumVulnerable Code
bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup npx skills add AgentPMT/agent-skills --skill agentpmt-no-account-agentaddress-x402Technical Analysis
The documented installation commands invoke
npx skillswithout specifying a reviewed package version or integrity hash. Depending on the local npm environment,npxmay retrieve and execute a mutable package from the npm registry. The referencedAgentPMT/agent-skillssource is also not pinned to an immutable commit or release.Consequently, the code and Skill content installed when these commands are run may differ from the versions reviewed during this audit. The document's freshness guidance also encourages reinstalling remote content, increasing exposure to future upstream changes.
This is a supply-chain weakness rather than evidence that the currently reviewed file contains an intentionally malicious payload.
Attack Path
- An attacker compromises the npm package resolved by
npx skills, its publisher account, the referenced remote repository, or another relevant distribution component. - The attacker publishes a modified package or Skill revision containing malicious installer behavior or instructions.
- An operator follows one of the documented unpinned installation commands.
npxretrieves the mutable package, and the tool retrieves the mutable Skill source.- Attacker-controlled installer code may execute with the invoking user's privileges, or attacker-controlled Skill instructions may be installed and subsequently loaded by the agent.
Impact Assessment
Successful compromise could permit code execution under the privileges of the user run ...[truncated 484 chars]
- An attacker compromises the npm package resolved by
- Remediation
View remediation
Remediation Suggestions
- Pin the npm package invoked through
npxto an exact, reviewed version rather than resolving the latest mutable release. - Use a lockfile with verified registry integrity metadata and retain it as part of the reviewed installation process.
- Pin remote Skill sources to immutable commit hashes or signed, versioned release artifacts.
- Publish and verify cryptographic checksums or signatures for downloaded Skill content before installation.
- Review package lifecycle scripts and disable unnecessary script execution during dependency installation where supported.
- Avoid running
npxinstallers in shared or privileged agent runtimes. Perform installation in an isolated, least-privileged environment. - Require a fresh security review before upgrading the installer package or referenced Skill revision.
- Pin the npm package invoked through
