T08 · Insecure Dependencies
- Location
SKILL.md:262- Finding
Unpinned Third-Party Installer and Mutable Skill Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 262-268
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code
bash npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setupbash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setupTechnical Analysis
The documented setup commands invoke the
skillsnpm package throughnpxwithout specifying an exact package version. They also install Skill content from the mutableAgentPMT/agent-skillssource without pinning an immutable commit, release, checksum, or cryptographic signature.Consequently, the components executed or installed when a user follows these instructions may differ from those present when this Skill was audited. This creates a supply-chain trust boundary: compromise of the npm package, its publishing account, the upstream repository, or its distribution infrastructure could cause users to execute or install attacker-controlled content.
This access exceeds the minimum privileges needed by the reviewed package itself, which is documentation-only and merely describes remote trade-data queries. The setup process introduces a local package execution and Skill-installation capability that is not intrinsically necessary to parse the schema or understand the supported query parameters.
Attack Path
- An attacker compromises the npm package, its publisher credentials, the
AgentPMT/agent-skillsupstream source, or another component in the installation chain. - The attacker publishes a modified installer or replaces the referenced Skill content with malicious instructions or executable setup behavior.
- A user follows the unpinned
npx skills add ...command fromSKILL.md. npxresolves the package available at execution time rather than a previously audited immut ...[truncated 944 chars]
- An attacker compromises the npm package, its publisher credentials, the
- Remediation
View remediation
Remediation Suggestions
- Pin the npm command to a specifically reviewed version, for example by using
npx skills@<exact-version>rather than an unversioned package reference. - Pin the AgentPMT Skill source to an immutable commit hash or cryptographically signed release instead of a mutable repository branch.
- Publish and verify cryptographic checksums or signatures for downloaded Skill content before installation.
- Use npm lockfiles and integrity metadata where the installation workflow supports them.
- Prefer a reviewed manual configuration procedure when only an MCP or REST endpoint must be configured, avoiding unnecessary local package execution.
- Run installation in a restricted environment with minimal filesystem, credential, network, and process permissions.
- Document the exact expected package version, source revision, downloaded files, and verification procedure so users can confirm that the installed content matches the audited release.
- Require explicit user confirmation before executing third-party installers or replacing existing Skills.
- Pin the npm command to a specifically reviewed version, for example by using
