T08 · Insecure Dependencies
- Location
SKILL.md:247- Finding
Unpinned Remote Skill Installer Creates a Supply-Chain Execution Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 247-257
Vulnerability Type: Unpinned third-party installer and mutable remote dependencies
Risk Level: MediumVulnerable Code
markdown - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext Equivalent unpinned commands are repeated at `SKILL.md:310-311`. ### Technical Analysis The documented setup procedure invokes the `skills` package through `npx` without specifying a package version. It also identifies remote Skill content by a mutable repository and Skill name rather than an immutable commit, signed release, or verified artifact digest. `npx` may download and execute the currently resolved package when a trusted local version is unavailable. Consequently, the effective installer code can change after this Skill has been reviewed. The subsequently installed setup Skills can also change independently of this package because their source revision is not pinned. This is particularly relevant because the installed components are intended to configure AgentPMT account, MCP, and REST connectivity. Although the reviewed files contain no malicious executable code and explicitly advise against exposing secrets, the unpi ...[truncated 1963 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the
skillsnpm package to a specifically audited version instead of relying on the latest registry resolution:bash npx --yes skills@<audited-version> add AgentPMT/agent-skills --skill what-is-agentpmt - Pin
AgentPMT/agent-skillsto an immutable commit hash or signed release tag supported by the installer. - Publish expected cryptographic checksums for downloaded artifacts and verify them before installation.
- Sign releases and require signature verification against a documented maintainer key.
- Use lockfiles and integrity metadata for all transitive dependencies involved in installation.
- Prefer a reviewed local copy of the required setup documentation where automatic remote installation is unnecessary.
- Document the exact files and permissions the installer requires, and advise users to run it without administrator privileges in an isolated environment.
- Add explicit guidance to inspect the resolved package version and remote revision before approving execution.
- Periodically review and update pinned versions through a controlled release process rather than silently accepting mutable upstream content.
- Pin the
