T08 · Insecure Dependencies
- Location
SKILL.md:342- Finding
Unpinned Third-Party Installation Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:342,SKILL.md:346,SKILL.md:351-352, andSKILL.md:405-406
Vulnerability Type: Unpinned third-party dependencies and mutable installation sources
Risk Level: MediumVulnerable Code
markdown - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setupTechnical Analysis
The documented setup procedure invokes an unversioned package through
npxand installs Skill content from the mutableAgentPMT/agent-skillsrepository reference. Neither the package runner version nor an immutable repository commit is specified.Consequently, the content downloaded and processed when a user runs these commands can differ from what existed during this audit. Compromise of the npm package, its publishing account, the upstream repository, or its maintainers could cause users to retrieve malicious code or agent instructions without any modification to the audited project.
This is a supply-chain weakness rather than evidence that the currently documented dependency is malicious.
Attack Path
- An attacker compromises the relevant npm package, package-publishing account, upstream repository, or maintainer account.
- The attacker publishes a malicious package version or modifies the Skill content referenced by
AgentPMT/agent-skills. - A user follows the setup instructions and runs one of the unpinned
npx skills addcommands. npxretrieves the current mutable package and repository content rather than a previously audited version.- The malicious dependency executes during installation or installs attacker-controlled Skill instructions.
- The payload operates with the privileges available to the inv ...[truncated 689 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the
npxpackage to a reviewed exact version instead of relying on the latest available release. - Pin
AgentPMT/agent-skillsto an immutable commit hash or signed release tag. - Publish cryptographic checksums or signatures for setup artifacts and verify them before installation.
- Avoid executing newly downloaded dependencies without inspection; where practical, vendor reviewed setup files with the Skill.
- Use package-locking and integrity metadata to make dependency resolution reproducible.
- Document the expected source, version, commit, and verification procedure alongside each installation command.
- Run installation with the least-privileged account possible and isolate it from unrelated credentials and sensitive files.
- Pin the
