T08 · Insecure Dependencies
- Location
SKILL.md:246- Finding
Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 246-267
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code
markdown If those setup skills are not installed beside this product skill, use the downloads below. Core AgentPMT setup skills: - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` - No-account AgentAddress/x402 setup: ../agentpmt-no-account-agentaddress-x402 - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-no-account-agentaddress-x402 - OpenClaw install: `openclaw skills install agentpmt-no-account-agentaddress-x402` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-no-account-agentaddress-x402` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup npx skills add AgentPMT/agent-skills --skill agentpmt-no-account-agentaddress-x402text ### Technical Analysis The Skill instructs users to invoke an unpinned npm-distributed CLI and install mutable Skill content from external sources. The commands do not identify a fixed CLI version, repository commit, release digest, checksum, or cryptographic signature. Consequently, the material installed at execution time may differ from the material that was reviewed during this audit. The freshness ...[truncated 1887 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the npm CLI to an explicitly reviewed version rather than invoking an unspecified latest release.
- Pin each external Skill to an immutable commit hash or signed release identifier.
- Publish SHA-256 or stronger checksums and verify them before installation.
- Require signed releases and verify signatures against documented maintainer keys.
- Use lockfiles or equivalent immutable dependency manifests where supported.
- Download and inspect setup Skills before activation, particularly Skills that handle accounts, authentication, payments, or wallets.
- Avoid automatic or time-based reinstallation without integrity verification and change review.
- Run installation in a sandbox with minimal filesystem, credential, network, and wallet access.
- Document the expected publisher identity, package name, version, repository, and verification procedure to reduce dependency-confusion and account-takeover risks.
