T08 · Insecure Dependencies
- Location
SKILL.md:187- Finding
Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 187–201
Vulnerability Type: Unpinned and unverified third-party dependency installation
Risk Level: Mediummarkdown Core AgentPMT setup skills: - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext ### Technical Analysis The documented installation commands retrieve skills from mutable external distribution channels without specifying a package version, immutable repository commit, checksum, or signature. Invoking `npx` can also retrieve and execute package tooling that is not pinned in the instructions. Consequently, the effective content installed by these commands can change after this Skill has been reviewed. A compromise of the package registry, upstream repository, publisher account, or skill distribution channel could cause users to receive content different from the audited version. The risk is elevated because the downloaded components concern AgentPMT account, MCP, and REST configuration. Such setup components may operate in an authentication-sensitive context. The audited project does not itself contain evidence that the current upstream packages are malicious; the vulnerability is the absence of integrity and ...[truncated 1715 chars]- Remediation
View remediation
Remediation Suggestions
- Pin every installation dependency to a reviewed, immutable package version and repository commit.
- Replace mutable commands with version-qualified forms supported by the relevant installer.
- Publish cryptographic checksums or signed release metadata and require verification before installation.
- Configure package tooling to enforce lockfiles, signature verification, and reproducible dependency resolution where supported.
- Avoid executing remotely retrieved setup tooling through
npxunless the exact package version and integrity are fixed. - Review the account-setup skills separately because they operate near authentication and API configuration boundaries.
- Run installation with a non-privileged account in an isolated environment and grant only the filesystem and network access required for setup.
- Do not automatically reinstall or update solely because the document's freshness period has elapsed; require explicit review and approval of the new version.
- Document the expected publisher identity, release version, commit hash, and verification procedure alongside each installation command.
