T08 · Insecure Dependencies
- Location
SKILL.md:44- Finding
Unpinned Third-Party npm Package Installation and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:44-48,SKILL.md:58-62, andSKILL.md:96
Vulnerability Type: Unpinned third-party dependencies and direct execution of remotely retrieved npm packages
Risk Level: MediumVulnerable Code
SKILL.md:44-48bash npm install agent-passport-system # SDK: /core subpath is the curated default npm install agent-passport-system-mcp # MCP server: APS_PROFILE=essential is the default go get github.com/aeoess/agent-passport-go@v0.7.0 # Go SDK, byte-parity subset (passport, delegation, attribution, completion, in-toto, values) pip install agent-passport-system==3.0.1 # Python SDK cargo add agent-passport-system@0.3.0 # Rust SDK, library crate agent_passportSKILL.md:58-62bash npx agent-passport-system-mcpRemote MCP (zero install):
https://mcp.aeoess.com/sseSKILL.md:96text Setup: `npx agent-passport-system-mcp setup` (auto-configures Claude Desktop + Cursor)Technical Analysis
The npm installation instructions do not pin
agent-passport-systemoragent-passport-system-mcpto exact versions and do not provide an integrity hash, signature-verification procedure, or committed lockfile. Consequently, the installed implementation is determined by mutable npm registry state at installation time rather than by the reviewed artifact.The
npx agent-passport-system-mcpandnpx agent-passport-system-mcp setupcommands present a more direct supply-chain risk becausenpxcan download and immediately execute the package selected from the registry. Package CLI code and applicable npm lifecycle behavior execute with the permissions of the user running the command.The
setupvariant is documented as automatically modifying Claude Desktop and Cursor configuration. If the retrieved package were compromised, this configuration access could be abused to register attacker-controlled age ...[truncated 2465 chars]- Remediation
View remediation
Remediation Suggestions
-
Pin every npm dependency and
npxinvocation to an exact reviewed version, for example:bash npm install --save-exact agent-passport-system@6.0.1 npm install --save-exact agent-passport-system-mcp@6.0.1 npx --yes agent-passport-system-mcp@6.0.1 -
Commit an npm lockfile containing registry integrity metadata and require reproducible installation through
npm cirather than unconstrainednpm install. -
Verify npm package provenance, publisher identity, signatures or attestations, and expected integrity hashes before execution. Document the verification procedure alongside the installation commands.
-
Prefer installing and reviewing the pinned package before invoking its CLI rather than allowing
npxto retrieve and execute an implicitly selected release in one step. -
Disable lifecycle scripts during dependency retrieval where compatible with package operation:
bash npm ci --ignore-scriptsIf scripts are required, enumerate and review them before enabling execution.
-
Run the MCP server and setup process in a least-privilege environment without unnecessary credentials, sensitive environment variables, or access to unrelated user files.
-
Replace automatic editor configuration with a preview-and-confirm workflow. Display the exact files and configuration entries that will be modified, create backups, and require explicit user approval before applying changes.
-
Publish or reference the corresponding source revision and build provenance for each released package so reviewers can associate the pinned registry artifact with auditable source code.
-
