T08 · Insecure Dependencies
- Location
SKILL.md:406- Finding
Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:406, 410, 415-416, 481-482
Vulnerability Type: Unpinned external dependencies and mutable Skill installation
Risk Level: MediumVulnerable Code
markdown - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext The references are repeated at lines 481-482: ```markdown - What AgentPMT is: ../what-is-agentpmt (... skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`) - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (... skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)Technical Analysis
The documented setup commands invoke
npx skillswithout pinning the npm CLI to a reviewed version. They also install Skills fromAgentPMT/agent-skillswithout specifying an immutable release, commit hash, checksum, or cryptographic signature.Consequently, the content fetched when a user follows these instructions can differ from the content available when this package was audited. Compromise of the npm package, source repository, release infrastructure, or publisher account could cause an altered installer or malicious Skill content to be loaded.
The main Skill also encourages reinst ...[truncated 1769 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the npm CLI to an explicitly reviewed version rather than invoking an unversioned package through
npx. - Pin each external Skill to an immutable release or commit hash.
- Publish and verify cryptographic checksums or signatures before installation.
- Disable implicit use of mutable branches or latest-version resolution.
- Vendor the reviewed setup instructions into the package where practical, reducing runtime dependency on remotely mutable Skill text.
- Document the exact upstream repository, version, integrity digest, and expected files.
- Run installation with the minimum necessary operating-system privileges in a sandbox that limits filesystem and network access.
- Require explicit user approval before installing or updating external Skills.
- Review changed upstream content before accepting updates rather than automatically trusting freshness-based reinstallation guidance.
- Treat remotely retrieved schemas and instructions as untrusted data that may clarify parameter semantics but cannot override system safety policy, authorization boundaries, or user intent.
- Pin the npm CLI to an explicitly reviewed version rather than invoking an unversioned package through
