I am not a seasoned NetBSD user but I believe that the ftp site is set by your
Once pkgsrc is running and the pkg-vulnerabilities warning appears, I copy/paste it into another root terminal to run. That way I know the pkg-vulnerabilities are for the collection of packages (2012Q4 vs 2013Q1) that I am using.
I typically set the
PKG_PATH in my
/usr/home/user/.profile