T08 · Insecure Dependencies
- Location
SKILL.md:513- Finding
Unpinned Third-Party Installation Commands Create a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 513-529
Vulnerability Type: Unpinned executable dependency and mutable Skill source
Risk Level: MediumEvidence
markdown If those setup skills are not installed beside this product skill, use the downloads below. Core AgentPMT setup skills: - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext ### Technical Analysis The installation instructions invoke an npm-delivered CLI through `npx` without specifying a reviewed version. They also install Skill content from a mutable repository reference without pinning an immutable commit or signed release. Consequently, the installed code or instructions may differ from the content reviewed during this audit. Compromise of the npm package, publisher account, upstream repository, or distribution channel could cause future installations to retrieve malicious content. The separate freshness instruction encouraging reinstallation increases exposure to mutable upstream changes. No evidence shows that the currently documented AgentPMT packages are malicious. The vulnerability is the absence of supply-chain integrity controls. ### Attack Path 1. An attacker compromises the ...[truncated 1076 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the npm CLI to a reviewed version, for example by using an exact version rather than an implicit latest release.
- Pin Skill sources to immutable commit hashes or cryptographically signed release artifacts.
- Publish expected SHA-256 checksums and require verification before installation.
- Disable or review npm lifecycle scripts where possible.
- Avoid automatically encouraging reinstallation solely based on elapsed time; instead, identify a specific signed release and its security status.
- Execute installation in a restricted environment without unnecessary credentials, filesystem access, or administrative privileges.
- Document the exact code and instructions that each setup dependency installs.
