T08 · Insecure Dependencies
- Location
SKILL.md:8- Finding
Automatic Execution of an Unverified Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 8–12; automatic startup is additionally documented at line 27
Vulnerability Type: Third-party dependency and supply-chain risk
Risk Level: MediumComplete Code Snippet
yaml metadata: openclaw: requires: bins: ["npx"] env: ["OOSMETRICS_API_KEY"] primaryEnv: "OOSMETRICS_API_KEY" install: npm: "@oosmetrics/mcp@1.0.1"The automatic execution behavior is documented separately:
text The MCP server is installed via `npx @oosmetrics/mcp@1.0.1` and starts automatically when this skill is loaded.Technical Analysis
Loading this Skill causes
npxto retrieve and execute the external package@oosmetrics/mcp@1.0.1. The executable source is not included in the audited project, and the project contains no package lockfile, package integrity hash, vendored source, or other mechanism through which the executed npm artifact can be verified against reviewed code.Pinning the dependency to version
1.0.1and identifying a public source repository reduce accidental version drift, but they do not independently prove that the npm artifact is identical to that repository's source. The child process also receives access toOOSMETRICS_API_KEYas a required environment variable.This finding does not establish that the named package is malicious. It establishes that the Skill automatically executes an external, unreviewed supply-chain component with access to a credential and the permissions available to the agent process.
Attack Path
- An attacker compromises the package publication account, npm artifact, distribution path, or another relevant supply-chain component.
- The user loads the Skill.
- The Skill invokes
npxto retrieve and execute@oosmetrics/mcp@1.0.1. - The compromised package executes with the local permissions and environment inherited by the MCP process.
- The packag ...[truncated 910 chars]
- Remediation
View remediation
Remediation Suggestions
- Vendor the exact MCP server source or package artifact into a controlled internal repository and perform a source review before deployment.
- Verify that the npm artifact corresponds to the referenced source repository and release tag.
- Use a lockfile and a verified cryptographic integrity hash rather than relying only on a version string.
- Avoid automatic
npxdownload-and-execute behavior when the Skill is loaded. Install the reviewed artifact through a controlled deployment process. - Run the MCP server in a restricted sandbox with read-only filesystem access where possible, no access to unrelated environment variables, and minimal operating-system permissions.
- Restrict outbound traffic to the documented API endpoint and deny arbitrary network destinations.
- Provide
OOSMETRICS_API_KEYonly to the isolated MCP process, ensure that it has the minimum available scope, and support prompt rotation and revocation. - Continuously scan and monitor the package, its transitive dependencies, publisher ownership, and release provenance for supply-chain changes.
