T08 · Insecure Dependencies
- Location
SKILL.md:227- Finding
Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 227–228
Vulnerability Type: Unpinned third-party dependencies from mutable sources
Risk Level: MediumVulnerable Code
bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setupTechnical Analysis
The documented setup procedure invokes the
skillsnpm package throughnpxwithout pinning a verified package version. It also installs Skill content from the mutableAgentPMT/agent-skillsrepository without specifying an immutable commit hash, signed release, or integrity checksum.Consequently, the content executed or installed when a user follows these instructions may differ from the content that existed when this Skill was audited. The installation also expands the trusted instruction and dependency surface beyond the two files included in this project.
Account setup may legitimately require an additional component, but retrieving mutable third-party content through an unpinned installer is not the minimum-risk method of providing that functionality. No evidence establishes that the current upstream package or repository is malicious; the vulnerability is the absence of controls preventing a future or compromised release from being trusted automatically.
Attack Path
- An agent or user follows the setup instructions in
SKILL.md. npxresolves the current available version of theskillspackage rather than a version reviewed with this project.- The installer retrieves the current contents of the mutable
AgentPMT/agent-skillsrepository. - An attacker who has compromised the npm package, repository, maintainer account, or distribution channel supplies modified installer or Skill content.
- The unverified content is installed and subsequently interpreted or executed as trusted Agent instructions.
- Depending on the installer an ...[truncated 1026 chars]
- An agent or user follows the setup instructions in
- Remediation
View remediation
Remediation Suggestions
- Pin the
npxpackage to a specific, reviewed version rather than resolving the latest release dynamically. - Pin
AgentPMT/agent-skillsto an immutable commit hash or cryptographically signed release. - Publish expected checksums or signatures and verify them before installation.
- Avoid automatic installation; require explicit user confirmation that identifies the source, version, requested permissions, and security implications.
- Prefer bundling the minimum audited setup instructions locally when feasible.
- Review installed setup Skills independently, especially any component that handles account credentials, MCP configuration, or REST authentication.
- Run installation with the least-privileged account available and prevent installers from accessing unrelated secrets or sensitive directories.
- Maintain a dependency allowlist and periodically reassess pinned versions for known vulnerabilities.
- Pin the
