T08 · Insecure Dependencies
- Location
SKILL.md:270- Finding
Unpinned Third-Party Installer Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:270, 274, 279-280, 335-336
Vulnerability Type: Unpinned executable dependency and mutable supply-chain source
Risk Level: MediumVulnerable Code
markdown - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setupThe same unpinned installation commands are repeated in the AgentPMT reference section.
Technical Analysis
The Skill directs users or agents to invoke
npxto obtain and execute third-party installer tooling and install content fromAgentPMT/agent-skills. Neither the installer package nor the requested Skill source is pinned to an immutable version or commit. The instructions also provide no checksum, signature, lockfile, or other integrity-verification mechanism.Consequently, the code executed when these commands are followed may differ from the content that existed when this Skill was audited. This creates a supply-chain trust boundary outside the reviewed project. The risk is heightened because one installed component configures AgentPMT account, MCP, and REST connectivity and may therefore participate in security-sensitive credential handling.
This audit did not establish that the external packages are currently malicious. The vulnerability is the unsafe reliance on mutable, remotely resolved executable dependencies without integrity controls.
Attack Path
- An attacker compromises the relevant package registry entry, upstream repository, maintainer account, release process, or transitive dependency.
- The attacker publishes or substitutes a malicious version while retaining the expected package or repository identity.
- A user or agent follows the commands documented in ` ...[truncated 1062 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the
npxpackage to a specific, audited version rather than relying on mutable resolution. - Pin
AgentPMT/agent-skillsto an immutable commit or signed release tag. - Publish and verify cryptographic checksums or signatures before executing or installing downloaded content.
- Document the exact trusted registry and repository source and disable unexpected fallback registries.
- Use a lockfile or equivalent integrity metadata for installer and transitive dependencies.
- Prefer a download-and-review workflow over directly executing remotely resolved content.
- Run installation in a restricted sandbox with no unnecessary secrets, filesystem access, or elevated permissions.
- Independently audit the account setup Skill because it operates near authentication and account-connectivity boundaries.
- Pin the
