T08 · Insecure Dependencies
- Location
SKILL.md:255- Finding
Unpinned Third-Party Setup Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 255–265
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code
markdown - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext ### Technical Analysis The documented setup process invokes `npx` and installs skills from a mutable external repository without specifying a reviewed package version, release tag, commit hash, or integrity digest. The fetched setup skills are not included in this project, so their effective contents and behavior could not be inspected during this audit. This is particularly security-sensitive because the external skills are intended to configure AgentPMT account, MCP, and REST connectivity. Changes to those dependencies after review could introduce unsafe instructions, credential-handling behavior, or executable setup logic that is not represented in the audited artifact. The demographic Skill itself does not contain embedded malicious code, but the unpinned installation route creates a supply-chain trust boundary that exceeds what can be verified from the two local Markdown files. ### Attack Path 1. An attacker compromises the referenced package, repository, publishing account, or mutable upstream branch. 2. The attacker modifies one of the setup skills or its installation behavior. 3. A user follows the documented `npx skills add` command. 4. The current upstream content is retrieved instead of a fixed, pr ...[truncated 935 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the CLI package and each installed skill to an immutable, reviewed version or commit hash.
- Publish and verify cryptographic integrity hashes or signed release metadata before installation.
- Avoid invoking an implicitly selected
npxpackage version; specify a trusted version explicitly. - Vendor security-sensitive setup instructions into the reviewed project where practical.
- Review setup-skill changes before updating pinned revisions.
- Run installation with minimum filesystem, network, and account permissions.
- Require explicit user confirmation before installing or executing externally retrieved setup content.
