T08 · Insecure Dependencies
- Location
SKILL.md:193- Finding
Unpinned third-party installation commands create a mutable supply-chain execution path
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 193-209
Vulnerability Type: Unpinned executable package and Skill dependencies
Risk Level: MediumVulnerable Code
markdown Core AgentPMT setup skills: - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext ### Technical Analysis The documented `npx skills add` commands do not pin the `skills` CLI to an audited version. They also identify the `AgentPMT/agent-skills` source without an immutable commit, release digest, checksum, or signature. Consequently, the content retrieved and processed when a user follows these instructions can differ from the content available when this Skill was reviewed. `npx` can download and execute a Node.js package when the package is not already installed locally. This creates a code-execution boundary involving mutable third-party infrastructure. The downstream Skill repository is also outside this artifact and was not available for audit. Although no evidence establishes that either dependency is currently malicious, the installation method exposes users to package-account compromise, repository compromise, malicious release replacement, and other supply-chain attacks. ### Attack Path ...[truncated 1475 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to a reviewed exact version, for example by using an explicit immutable package version rather than allowing
npxto resolve the latest release. - Pin
AgentPMT/agent-skillsto an immutable commit hash or cryptographically signed release instead of a mutable repository reference. - Publish and verify SHA-256 checksums or signed provenance for all downloaded artifacts before execution.
- Use
npxoptions and package-manager configuration that prevent unexpected version resolution and lifecycle-script execution where compatible with the installer. - Vendor reviewed setup instructions or dependencies into a controlled distribution when practical.
- Execute installation in a sandbox or least-privileged environment without unrelated credentials or sensitive filesystem access.
- Document the exact trusted publisher, version, commit, checksum, and verification procedure so users can independently validate the dependency chain.
- Re-audit the pinned dependencies whenever their versions or immutable references change.
- Pin the CLI to a reviewed exact version, for example by using an explicit immutable package version rather than allowing
