T08 · Insecure Dependencies
- Location
SKILL.md:236- Finding
Unpinned Third-Party Skill Installation Permits Supply-Chain Code Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 236-260
Vulnerability Type: Unpinned third-party dependencies installed throughnpx
Risk Level: MediumThe affected instructions include:
markdown Core AgentPMT setup skills: - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext ### Technical Analysis The Skill instructs users to run `npx` and install skills from mutable package and repository references. The commands do not pin an exact package version, immutable repository commit, or cryptographic integrity digest. Consequently, the code retrieved and executed during installation can differ from the content available when this Skill was audited. `npx` may download and execute package code on the local system. Likewise, installing a named remote skill without an immutable revision delegates trust to the package registry, repository, publisher accounts, and their future releases. If any part of this supply chain is compromised, malicious setup code could execute under the invoking user's account. The Skill also advises users to reinstall it when its freshness period expires. Reinstalling from an unpinned source increases exposure to later changes that were not part of the reviewed artifact. No evidence shows th ...[truncated 1449 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the installer package to an exact, reviewed version instead of allowing
npxto resolve the latest release. - Pin each external skill to an immutable repository commit or signed release artifact.
- Publish and verify cryptographic checksums or signatures before installation.
- Use a trusted package registry with provenance verification and package-lock enforcement.
- Prefer installation modes that do not execute lifecycle scripts unless those scripts have been reviewed and are strictly necessary.
- Document the expected publisher, package version, commit identifier, and integrity digest so users can verify the retrieved artifact.
- Run installation with a dedicated, least-privileged account and without unrelated credentials in the environment.
- Require security review before updating pinned versions rather than automatically trusting newly published content.
- Pin the installer package to an exact, reviewed version instead of allowing
