T08 · Insecure Dependencies
- Location
SKILL.md:278- Finding
Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 278–293
Vulnerability Type: Unpinned third-party dependencies and remotely retrieved skills
Risk Level: MediumVulnerable Code
text Core AgentPMT setup skills: - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext ### Technical Analysis The setup instructions retrieve third-party packages and skills without pinning the npm command-line package to an exact version or pinning the remote skills repository to an immutable commit. No checksum, signature, or other integrity verification is specified. Consequently, the content installed when a user runs these commands can differ from the content available when this artifact was audited. If the npm package, ClawHub entry, source repository, publisher account, or distribution infrastructure is compromised, the installation can introduce attacker-controlled code or Skill instructions. This is a supply-chain weakness rather than evidence of an embedded malicious payload in the current project. The project itself contains only Markdown files, and no malicious local script was identified. ### Attack Path 1. An attacker compromises an upstream package, skills repository, ...[truncated 1312 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the
skillsnpm package to an audited exact version instead of invoking an unspecified current release. - Pin
AgentPMT/agent-skillsto an immutable commit hash, signed release, or content digest. - Pin OpenClaw-installed skills to immutable versions where the package manager supports version constraints.
- Publish expected SHA-256 checksums or cryptographic signatures and require verification before installation.
- Vendor reviewed setup instructions within the project when feasible, reducing dependence on mutable remote content.
- Display the resolved source, version, permissions, and integrity information and require explicit user confirmation before installation.
- Run installation in a sandbox or least-privileged environment without unnecessary credentials or access to sensitive files.
- Re-audit downloaded skills and their transitive dependencies before enabling them in production.
- Pin the
