T08 · Insecure Dependencies
- Location
SKILL.md:293- Finding
Unpinned Third-Party Installation Commands Create a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed remote agriculture-data connector with no malicious local behavior found, but users should be careful with paid calls and unpinned setup installs.
Install only when you intend to use AgentPMT for paid agriculture and food-security data queries. Prefer reviewed or pinned installation paths for the referenced setup skills, review those setup skills before entering account credentials, and keep secrets, wallet material, and payment headers out of prompts and logs.
SKILL.md:293Unpinned Third-Party Installation Commands Create a Supply-Chain Risk
The activation keywords include broad phrases like general research requests about food security, crop yields, and agricultural productivity. Overbroad trigger language can cause unintended auto-selection of this remote tool in ordinary conversations, increasing the chance of unnecessary external calls, data disclosure in prompts, or unreviewed paid actions.
The skill instructs users to install supporting skills via npx skills add ... without pinning a specific package or repository version. This creates a supply-chain risk: a later malicious or compromised package/revision could be fetched and executed during installation, especially because npx resolves live remote content at install time.
This line repeats an unpinned npx skills add ... installation path for a dependency skill. Because the fetched package/version is not fixed, users may install changed or malicious code in the future, turning documentation into an indirect code-execution vector.
The installation example again uses npx skills add with no version pinning for what-is-agentpmt. Even though this is documentation, it can still lead operators to execute unreviewed remote package content if the upstream package changes or is compromised.
This command similarly installs agentpmt-account-mcp-rest-api-setup via a floating npx invocation. That exposes users to supply-chain compromise and inconsistent behavior across time because the exact executed code is not fixed.
The reference section repeats an unpinned npx skills add command. Repetition increases the likelihood that users will copy and run a non-reproducible install command, inheriting any future upstream compromise.
This unversioned npx skills add command poses the same supply-chain risk as the earlier instances. Since it relates to account/MCP setup, compromise here could be especially sensitive because the installed code may later handle credentials or broker remote tool access.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/agriculture-food-security
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/agriculture-food-security
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
No suspicious patterns detected.