T08 · Insecure Dependencies
- Location
SKILL.md:33- Finding
Unpinned Third-Party Packages Executed Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 27, 31, 33–38, 56, 65, 74, 85, 92, and 97–104
Vulnerability Type: Supply-chain exposure caused by mutable, unverified dependencies
Risk Level: MediumComplete Code Snippet
The primary installation block appears at
SKILL.md:33–38:bash skills.sh install script: ```bash npx skills add AgentPMT/agent-skills --skill what-is-agentpmt npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setuptext The same unpinned installation pattern is used for the operational integrations: ```text npx skills add AgentPMT/agent-skills --skill get-users-current-time-date npx skills add AgentPMT/agent-skills --skill plaud npx skills add AgentPMT/agent-skills --skill google-calendar npx skills add AgentPMT/agent-skills --skill google-sheetsThe skill also recommends reinstalling mutable external components:
text If the current date is more than 7 days after the last updated date, reinstall this skill from skills.sh or ClawHub before relying on endpoints, schemas, setup steps, or examples.Technical Analysis
The documented commands invoke
npx skillswithout specifying a reviewed version of theskillspackage. Depending on local npm behavior and cache state,npxcan retrieve and execute the current package version from the configured registry.The
AgentPMT/agent-skillssource is also referenced without an immutable release tag, commit hash, integrity digest, or signature. Consequently, the code and instructions installed by these commands can change after this skill has been audited. The project contains no lockfile, vendored dependency copy, checksum manifest, or other mechanism that binds installation to reviewed content.This is an insecure dependency and supply-chain pattern rather than evidence that the current external packages are malicious. Exploitation requires compromise or malicious mod ...[truncated 1909 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the
skillsCLI to an explicitly reviewed version, for examplenpx skills@<reviewed-version>, rather than resolving the latest available release. - Pin
AgentPMT/agent-skillsto an immutable commit hash or cryptographically signed release instead of a mutable repository reference. - Publish and verify integrity hashes or signatures for every installed skill artifact.
- Maintain a lockfile or a reviewed, vendored copy of required dependencies so installations are reproducible.
- Replace automatic freshness-based reinstall guidance with a controlled update process that reviews changes before deployment.
- Run installation in a restricted sandbox without Plaud, Google, AgentPMT, or unrelated local credentials in the environment.
- Apply least-privilege OAuth scopes to Plaud, Google Calendar, and Google Sheets integrations, and keep package installation separate from authenticated workflow execution.
- Review transitive dependencies and package lifecycle scripts before approving each dependency update.
- Pin the
