T08 · Insecure Dependencies
- Location
SKILL.md:291- Finding
Unpinned Third-Party Skill Installation Creates a Mutable Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s labor-data feature is legitimate, but its setup instructions rely on mutable unpinned installs that users should review before running.
Install only if you are comfortable with AgentPMT remote calls and credit usage. Avoid sending secrets or sensitive personal data in tool parameters, and do not run the npx setup commands unless you can verify the package, source revision, and related setup skills you are installing.
SKILL.md:291Unpinned Third-Party Skill Installation Creates a Mutable Supply-Chain Risk
The activation keywords are broad enough to match many generic labor or research requests, which can cause this remote-tool skill to be selected when a user only wanted general analysis. In context, that can unintentionally route user data or queries to an external paid service, increasing privacy, cost, and tool-confusion risk.
The skill instructs users to run npx skills add ... without pinning an exact package/version, which creates a supply-chain risk: a later malicious or compromised package release could be fetched and executed at install time. Because npx may download and run code directly from the registry, this can lead to arbitrary code execution on the installing host.
This is another unpinned npx skills installation instruction, so the same package-supply-chain exposure applies here. An attacker who compromises the package, its dependency tree, or the referenced distribution path could cause users to execute unintended code during setup.
The install script includes npx skills without version pinning, exposing users to arbitrary upstream changes or malicious releases. Since these commands are presented as copy-paste setup steps, they materially increase the chance of unsafe execution.
This repeated unpinned npx skills command carries the same supply-chain and arbitrary code execution risk as the other occurrences. Repetition in the skill increases exposure because users may follow any one of several unsafe install examples.
The reference section again directs users to npx skills add ... without an exact version, preserving the same package-resolution risk. Even though it appears in a reference block, users may still execute it verbatim, leading to execution of unreviewed code.
This unpinned package execution instruction is a true supply-chain weakness for the same reasons as the other RP1 findings. The skill provides installation commands in multiple places, multiplying opportunities for a user to run an unsafe, non-reproducible command.
The skill explicitly directs data transmission to external AgentPMT endpoints. Although expected for a remote data product, it is still a true external-transmission risk because user-supplied inputs may leave the local environment and be processed by a third party, with associated privacy, compliance, and logging implications.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/labor-market-employment
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
This line references the AgentPMT REST invoke endpoint, confirming that tool use involves outbound transmission to an external service. In this skill's context the transmission is functional rather than malicious, but it still matters because mis-scoped inputs, secrets, or sensitive business context could be disclosed to the remote provider.
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/labor-market-employment
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
No suspicious patterns detected.