T08 · Insecure Dependencies
- Location
SKILL.md:193- Finding
Unpinned Third-Party Proxy Packages Are Automatically Downloaded and Executed
- Content
View full analysis
``` ### Technical Analysis The legacy transport configurations invoke `mcp-remote` and `supergateway` through `npx -y` without specifying exact package versions or verifying package integrity. The `-y` option suppresses the normal installation confirmation, while the absence of a version constraint allows npm to resolve and execute a package release that may differ from the one reviewed when the Skill was published. This creates a supply-chain execution boundary controlled by mutable external npm packages. If a package, package maintainer account, or package publication process is compromised, the resolved package can execute arbitrary JavaScript under the permissions of the user running the MCP client. The proxy packages are only needed for clients that do not support native Streamable HTTP. Automatically downloading mutable packages therefore exceeds the minimum privileges and trust required for clients that can connect directly. ### Attack Path 1. An attacker compromises the npm account, publication pipeline, or release artifacts of `mcp-remote` or `supergateway`. 2. The attacker publishes a malicious version under the legitimate package name. 3. A user installs the documented legacy MCP configu ...[truncated 799 chars]- Remediation
View remediation
` or `supergateway@`. 3. Remove `-y` so installation requires explicit user approval. 4. Install dependencies separately using a lockfile and verify registry integrity hashes before execution. 5. Document the expected package publisher, version, checksum, and official source repository. 6. Run unavoidable proxy software in a restricted environment with minimal filesystem, network, and credential access. 7. Establish a dependency review and update process rather than resolving the latest package automatically at runtime. ]]>
