T08 · Insecure Dependencies
- Location
SKILL.md:353- Finding
Unpinned Third-Party Installer and Skill Retrieval
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 353–354
Vulnerability Type: Unpinned remote supply-chain dependency
Risk Level: MediumVulnerable Code
bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setupTechnical Analysis
The Skill instructs users or agents to invoke an npm-delivered CLI through
npxand install additional Skills from the mutableAgentPMT/agent-skillssource. Neither the CLI nor the retrieved Skill content is pinned to a reviewed package version, commit hash, checksum, or cryptographic signature.Consequently, the code and instructions executed or installed at setup time may differ from the content that was originally audited. This creates a supply-chain trust boundary: compromise of the npm package, its transitive dependencies, the remote repository, or its publisher account could result in modified code or malicious Skill instructions being delivered to users.
The remote installation is related to configuring the declared hosted service, but executing mutable third-party content without integrity controls exceeds the minimum privilege necessary. A safer setup can use pinned, independently verified artifacts.
Attack Path
- An attacker compromises the
skillsnpm package, one of its dependencies, the referenced remote repository, or a relevant publisher account. - The attacker publishes or introduces altered installer code or malicious Skill content.
- A user follows the documented setup procedure and executes one of the unpinned
npx skills addcommands. npxresolves the current package version, and the installer retrieves mutable content from the remote source.- The compromised component executes with the invoking user's privileges or installs malicious instructions that affect later agent sessions.
This path depends on an upstream supply-chain compromise; the audited project itself c ...[truncated 809 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin the
skillsCLI to a reviewed exact version instead of allowingnpxto resolve the latest release. - Pin
AgentPMT/agent-skillsto an immutable commit hash or signed release tag. - Publish and verify cryptographic checksums or signatures for all downloaded artifacts before installation.
- Use a lockfile and integrity metadata for npm dependencies, including transitive dependencies.
- Avoid automatic execution of remotely retrieved content; download, inspect, verify, and then install it as separate steps.
- Run the installer in a sandbox or least-privileged environment without access to unrelated credentials or sensitive files.
- Document the expected artifact digest and provide a procedure for validating publisher signatures and repository ownership.
- Review the two setup Skills independently before enabling them in production agent environments.
- Pin the
