T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Third-Party MCP Package Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:13-15
Vulnerability Type: Unpinned executable dependency
Risk Level: MediumVulnerable Code:
yaml install: - kind: node package: "@indigoprotocol/cardano-mcp"Technical Analysis
The skill instructs the runtime to install the npm package
@indigoprotocol/cardano-mcpwithout specifying an exact version or integrity hash. Consequently, the package contents installed in the future may differ from those available when the skill was audited.The repository does not contain the package source, a lockfile, an integrity value, or other controls that would allow the installed artifact to be verified against a reviewed version. Because npm packages can contain lifecycle scripts and executable runtime logic, a compromised or unexpectedly modified release could execute code with the privileges granted to the skill process.
There is no evidence in the audited files that the named package is currently malicious. The vulnerability is the mutable and unverifiable trust relationship created by the unpinned installation configuration.
Attack Path
- An attacker compromises the npm publisher account, package distribution channel, or a future package release.
- The attacker publishes a modified version of
@indigoprotocol/cardano-mcp. - The skill installation process resolves the package without an exact version or integrity constraint.
- The modified package is installed and its lifecycle or runtime code executes.
- The package accesses the process environment, wallet credential, filesystem, or network resources available to the MCP process.
- The attacker may exfiltrate sensitive information or perform actions under the process account's permissions.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the account running the skill or MCP server. Because the skill also ...[truncated 286 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to an exact, reviewed version rather than allowing mutable resolution:
yaml install: - kind: node package: "@indigoprotocol/cardano-mcp" version: "X.Y.Z" - Use a lockfile containing package integrity hashes and verify it during installation.
- Obtain the package only from a trusted registry and validate package provenance or signed release metadata where supported.
- Review the selected package version, including lifecycle scripts and transitive dependencies.
- Disable npm lifecycle scripts when they are unnecessary.
- Run the MCP server in a restricted environment with minimal filesystem access, outbound network access, and environment variables.
- Introduce an update-review process so dependency upgrades are explicitly audited before deployment.
- Pin the dependency to an exact, reviewed version rather than allowing mutable resolution:
