T08 · Insecure Dependencies
- Location
SKILL.md:188- Finding
Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 188-202
Vulnerability Type: Unpinned third-party dependencies and installation tooling
Risk Level: MediumVulnerable Code
markdown Core AgentPMT setup skills: - What AgentPMT is: ../what-is-agentpmt - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt - OpenClaw install: `openclaw skills install what-is-agentpmt` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt` - AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup` - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup` skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext ### Technical Analysis The documented installation commands invoke an npm-delivered CLI through `npx` without specifying a verified package version. They also retrieve skills from `AgentPMT/agent-skills` without pinning the source to an immutable commit or release. Consequently, the effective content installed by these commands can change after this Skill has been reviewed. The audit cannot establish that a future npm package version, repository revision, or downloaded setup skill will retain the behavior observed in the current artifact. This creates a supply-chain trust boundary outside the audited project. The commands are presented as setup instructions rather than being executed automatically by the two files in scope. Exploitation therefore requires a user or agent to follow the installation instructions. ### Attack Path 1. An attacker compromises the npm package, its publisher credentials, th ...[truncated 987 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the npm CLI to a reviewed, exact version instead of allowing
npxto resolve the latest release. - Pin downloaded skill repositories to immutable commit hashes or cryptographically signed release tags.
- Publish and verify integrity hashes for all remotely obtained artifacts.
- Use package lockfiles or an equivalent dependency-locking mechanism where applicable.
- Require explicit user confirmation before running installation commands or adding new skills.
- Review downloaded content before activation and prevent newly installed skills from inheriting unnecessary tools or credentials.
- Document the exact trusted publisher, version, commit, and expected integrity value in
SKILL.md.
- Pin the npm CLI to a reviewed, exact version instead of allowing
