T08 · Insecure Dependencies
- Location
SKILL.md:319- Finding
Unpinned Third-Party Installation Commands Create Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 319-331
Vulnerability Type: Unpinned third-party package and Skill installation
Risk Level: MediumVulnerable Code
text Core AgentPMT setup skills: - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext ### Technical Analysis The Skill recommends executing `npx` and OpenClaw installation commands without pinning the installer package, downloaded Skills, repository revision, or release version. It also provides no checksum, signature, or other integrity-verification mechanism. `npx` can download and execute the package version currently resolved by the package registry. Likewise, the named Skills can change after this project has been audited. Consequently, the code and instructions ultimately installed by these commands are not immutable and may differ from the content that was reviewed. This is a supply-chain weakness rather than evidence that the current dependencies are malicious. Exploitation requires a registry package, publisher account, repository, distribution channel, or later dependency release to become compromised. The commands are documented setup steps and are not executed automatically by the audited ...[truncated 1668 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the
npxinstaller package to an exact, audited version rather than relying on the registry's current resolution. - Pin each setup Skill to an immutable commit, content digest, or signed release.
- Publish and verify cryptographic checksums or signatures before installation.
- Use lockfiles or an equivalent dependency manifest where supported.
- Avoid install commands that implicitly execute newly downloaded code without displaying and verifying the resolved source and version.
- Document the expected publisher, repository, version, and digest so users can detect substitution.
- Review dependency updates before changing pinned versions, rather than advising users to retrieve an unspecified latest release.
- Run installation with the minimum required user privileges and avoid administrator or root execution.
- Pin the
