T08 · Insecure Dependencies
- Location
SKILL.md:343- Finding
Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:343-353
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
markdown Core AgentPMT setup skills: - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext ### Technical Analysis The documented setup procedure invokes an npm-distributed CLI through `npx` and installs skill content from an external repository without specifying immutable versions, commit hashes, package integrity values, or cryptographic signatures. Because the referenced components are mutable, the content executed or installed when a user follows these instructions may differ from the content that was available during this audit. This creates a supply-chain trust boundary in which compromise of the npm package, repository, publisher account, or distribution infrastructure could introduce unauthorized code or malicious skill instructions. The installation is not inherently unnecessary for the declared hosted-service functionality, but the absence of version and integrity pinning exceeds a safe minimum-trust design. ### Attack Path 1. An attacker compromises the npm package, upstream repository, publisher a ...[truncated 1033 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the npm CLI to an audited exact version rather than relying on the latest resolution.
- Pin external skill content to an immutable release tag or commit hash.
- Publish and verify cryptographic checksums or signatures for downloaded packages and skill files.
- Disable npm lifecycle scripts where they are not required and review all scripts before installation.
- Prefer vendored, locally audited setup documentation over dynamically downloaded instructions.
- Execute installation in a restricted environment with minimum filesystem, credential, and network access.
- Document the expected publisher identity and provide a verification procedure before users execute the command.
