T08 · Insecure Dependencies
- Location
SKILL.md:247- Finding
Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 247-257
Vulnerability Type: Unpinned third-party dependencies from a mutable remote source
Risk Level: MediumVulnerable Code
markdown - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext The same mutable installation recommendations are repeated at `SKILL.md:318-319`. ### Technical Analysis The Skill instructs users to execute `npx` and install two additional Skills from `AgentPMT/agent-skills` without pinning the CLI version, repository commit, release tag, or artifact integrity digest. Consequently, the content installed at a future date may differ from the content reviewed when this Skill was audited. The setup Skills are especially security-sensitive because one is explicitly responsible for AgentPMT account, MCP, and REST configuration. If the upstream repository, package publication process, dependency-resolution infrastructure, or maintainer account is compromised, altered content could be delivered through these documented installation commands. This is a supply-chain weakness rather than evidence that the currently referenced dependencies are malicious. ### Attack Path 1. An attacker compromises the referenced repository, package publication acco ...[truncated 1693 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the
npxCLI package to a reviewed, exact version rather than allowing resolution of the latest release. - Pin
AgentPMT/agent-skillsto an immutable commit hash or cryptographically signed release. - Publish and verify SHA-256 or stronger integrity digests for downloaded artifacts before installation.
- Require signature verification and fail closed when a signature, version, or digest does not match.
- Replace automatic reinstall guidance with an explicit update-and-review process.
- Review the downloaded Skill files before activation, particularly any setup component that handles account credentials or connection configuration.
- Run installation in a sandbox with restricted filesystem, environment-variable, credential-store, and network access.
- Maintain a dependency manifest recording reviewed versions, source commits, hashes, and review dates.
- Avoid granting downloaded setup Skills access to wallet secrets, private keys, mnemonics, payment headers, or unrelated account data.
- Pin the
