T08 · Insecure Dependencies
- Location
scripts/gitmcp.py:56- Finding
Unpinned npm Package Is Automatically Retrieved and Executed
- Content
View full analysis
Vulnerability Details
File Location:
scripts/gitmcp.py, lines 56-66 and 90-100
Vulnerability Type: Unpinned third-party package execution
Risk Level: HighVulnerable Code
python proc = subprocess.Popen( ["npx", "-y", "mcp-remote", mcp_url], stdin=subprocess.PIPE, stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True, bufsize=1 )The same invocation is used by both
list_tools()andcall_tool().Technical Analysis
Every supported operation launches
mcp-remotethroughnpxusing the-yoption. The package has no exact version, lockfile, integrity hash, or locally reviewed installation associated with it. Consequently, npm may resolve, download, and execute a package version that was not present when this Skill was audited.The
-yoption suppresses the interactive installation confirmation. This turns normal use of the Skill into an automatic third-party code execution path. If the npm package, one of its dependencies, or the relevant registry resolution is compromised, malicious installation scripts or runtime code can execute under the account running the Skill.Attack Path
- An attacker compromises the published
mcp-remotepackage, its maintainer account, or a transitive dependency. - A malicious package version is made available through npm resolution.
- A user or agent runs any documented command, such as
list-tools,fetch-docs, orsearch-code. - The script invokes
npx -y mcp-remotewithout an exact version constraint. npxresolves and may automatically download the compromised package.- The package executes locally with the privileges and environment of the user running the Skill.
Impact Assessment
Successful supply-chain exploitation can result in arbitrary code execution with the current user's privileges. Depending on the execution environment, the malicious package could access readable project ...[truncated 262 chars]
- An attacker compromises the published
- Remediation
View remediation
Remediation Suggestions
- Add
mcp-remoteas a declared project dependency pinned to a reviewed exact version. - Commit the appropriate lockfile and use deterministic installation, such as
npm ci. - Verify package integrity through lockfile integrity metadata and trusted registry configuration.
- Install dependencies during a controlled deployment step rather than during each Skill invocation.
- Invoke the locally installed, pinned executable instead of using
npx -y. - Audit the selected package version and its transitive dependencies before deployment.
- Run the bridge in a restricted environment with minimal filesystem, environment-variable, credential, and network access.
- Establish an explicit dependency-update review process so package upgrades cannot silently alter executed code.
- Add
