T08 · Insecure Dependencies
- Location
SKILL.md:115- Finding
Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 115-125
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code
markdown - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext ### Technical Analysis The Skill directs users or agents to execute an unpinned package through `npx` and install skills from a mutable repository reference. It does not specify an exact `skills` package version, an immutable AgentPMT repository commit, or an integrity checksum. Consequently, the components executed or installed during setup can differ from those reviewed in this project. The additional account-setup skill is relevant to accessing the hosted service, but importing mutable third-party content expands the trusted computing base and exceeds the minimum-risk approach to dependency installation. No evidence shows that the current dependency is malicious. The vulnerability is the absence of version and integrity controls, which exposes installation to future package compromise, repository compromise, maintainer-account takeover, or malicious updates. ### Attack Path 1. The referenced setup skills are absent from the local environment. 2. An agen ...[truncated 1176 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the
skillsnpm package to an exact reviewed version rather than allowingnpxto resolve a mutable release. - Pin the AgentPMT skill repository to an immutable commit hash or cryptographically signed release.
- Publish and verify SHA-256 checksums or signatures for all installed skill artifacts.
- Require explicit user confirmation before downloading or installing additional skills.
- Avoid automatic installation during ordinary invocation; provide reviewed, bundled setup documentation where practical.
- Run installation in a restricted environment without access to unrelated credentials or sensitive files.
- Re-audit dependency updates before changing pinned versions.
- Pin the
