T08 · Insecure Dependencies
- Location
SKILL.md:273- Finding
Unpinned Remote Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 273-286
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
markdown Core AgentPMT setup skills: - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext ### Technical Analysis The installation instructions invoke an `npx`-resolved package and retrieve skills from `AgentPMT/agent-skills` without specifying an immutable package version, release tag, commit hash, checksum, or signature. Consequently, the content installed by these commands can change after this Skill has been audited. If the package resolved by `npx`, its package-publishing account, the referenced repository, or another component of the distribution chain is compromised, a later invocation could install unreviewed or malicious content. Because installed skills can influence subsequent Agent behavior and may direct additional tool calls, this creates a supply-chain trust boundary outside the audited project. The project does not itself contain an embedded malicious script, and the documented AgentPMT network calls are consistent with its declared remote governance-data functionality. The issue is specifica ...[truncated 1510 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the
npxpackage to a reviewed, exact version rather than resolving the latest available release. - Pin
AgentPMT/agent-skillsto an immutable commit hash or cryptographically signed release. - Publish and verify SHA-256 checksums or signatures for downloaded skill artifacts before installation.
- Avoid automatic execution of remotely retrieved installation tooling where a verified local installer is available.
- Require users to inspect the resolved package and skill content before granting access to credentials, files, network tools, or other privileged capabilities.
- Run installation in a sandbox or least-privileged environment and disable unnecessary lifecycle scripts where the package manager supports doing so.
- Document the expected package version, repository commit, signer identity, and verification procedure directly in
SKILL.md.
- Pin the
