T08 · Insecure Dependencies
- Location
SKILL.md:225- Finding
Unpinned Remote Dependencies Executed Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 225-226
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code
bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setupTechnical Analysis
The setup instructions direct users to invoke a remotely resolved
npxpackage and install skills from an external source without pinning an exact package version, immutable repository commit, or integrity hash. Consequently, the dependencies executed or installed when a user follows these instructions may differ from those available when this Skill was audited.This is a supply-chain risk rather than evidence that the current upstream dependencies are malicious. Exploitation requires compromise of the relevant package, publisher account, distribution channel, or mutable upstream content. The commands are documented setup steps and are not automatically executed by the audited files.
Attack Path
- An attacker compromises the package publisher, registry entry, source repository, or another mutable component in the dependency chain.
- The attacker publishes a malicious version or modifies the remotely retrieved Skill content.
- A user follows the documented setup instructions and runs one of the unpinned
npxcommands. npxresolves and executes the currently available package rather than an immutable, previously reviewed version.- The compromised installer or installed Skill executes attacker-controlled behavior under the invoking user's permissions.
Impact Assessment
Successful exploitation could execute arbitrary code with the privileges of the user running
npx. Depending on that user's environment and permissions, this could expose accessible files, credentials, API tokens, agent configuration, or network resources and could modify locally wri ...[truncated 198 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the
npxpackage to an exact, reviewed version instead of relying on mutable resolution. - Pin installed Skill content to an immutable repository commit or signed release.
- Publish and verify cryptographic integrity hashes or signatures before installation.
- Use a locked dependency manifest where supported and review all transitive dependencies.
- Prefer downloading and inspecting the package before execution rather than allowing retrieval and execution in one step.
- Document the expected registry, publisher identity, source repository, version, and checksum so users can validate provenance.
- Run installation with the least-privileged account available and avoid administrator or root execution.
- Pin the
