T08 · Insecure Dependencies
- Location
SKILL.md:1273- Finding
Unpinned Third-Party Setup Dependencies Can Execute Mutable Upstream Code
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 1273–1277
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Mediumbash skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup npx skills add AgentPMT/agent-skills --skill agentpmt-no-account-agentaddress-x402Technical Analysis
The documented setup procedure invokes
npxwithout pinning theskillsCLI package or theAgentPMT/agent-skillsrepository to an immutable package version, release artifact, or commit hash. Consequently, the code and content resolved when a user follows these instructions may differ from what was available when this Skill was audited.This creates a supply-chain trust boundary in which compromise of the package registry entry, source repository, maintainer account, or a later upstream release could introduce attacker-controlled code. Because
npxexecutes the resolved CLI locally, malicious package initialization or CLI code could run with the privileges of the user performing the installation.Attack Path
- An attacker compromises an upstream package, repository, release process, or maintainer account used by the documented commands.
- The attacker publishes a malicious version or modifies the mutable upstream source.
- A user follows the setup instructions and runs one of the unpinned
npx skills addcommands. npxresolves and executes the current third-party CLI package rather than an audited immutable version.- The malicious dependency executes in the user's environment or installs attacker-controlled Skill instructions for subsequent use.
Impact Assessment
Successful exploitation could provide code execution with the permissions of the user running
npx. Depending on the execution environment and its existing controls, this may permit ...[truncated 614 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the
skillsCLI to a reviewed exact version instead of relying on the version selected dynamically bynpx. - Pin
AgentPMT/agent-skillsto an immutable commit hash or signed release rather than a mutable repository reference. - Publish and verify cryptographic checksums or signatures for downloaded installation artifacts.
- Use package-lock or equivalent integrity metadata where supported.
- Disable dependency lifecycle scripts where they are unnecessary, and document any scripts that must execute.
- Run installation in a sandbox with minimal filesystem, credential, and network access.
- Provide users with a verification procedure showing the expected package version, repository commit, signer identity, and artifact checksum before execution.
- Review and repin dependencies through a controlled update process whenever upstream versions change.
- Pin the
