T08 · Insecure Dependencies
- Location
SKILL.md:124- Finding
Unpinned Third-Party Packages Are Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:42, 64, 74, 80, 86, 97, 127-129, 140-141;README.md:12, 20, 26, 74-75
Vulnerability Type: Unpinned package execution and supply-chain exposure
Risk Level: MediumComplete Code Snippets
SKILL.md:62-64:bash uv tool run fulcra-api --helpSKILL.md:78-86:bash uv tool run fulcra-api auth login --get-auth-urlbash uv tool run fulcra-api auth login --device-code <DEVICE_CODE> --poll-timeout=5SKILL.md:124-130:json { "mcpServers": { "fulcra_context": { "command": "npx", "args": ["-y", "mcp-remote", "https://mcp.fulcradynamics.com/mcp"] } } }SKILL.md:137-143:json { "mcpServers": { "fulcra_context": { "command": "uvx", "args": ["fulcra-context-mcp"] } } }README.md:10-12:bash uv tool run fulcra-api auth loginREADME.md:71-77:json { "mcpServers": { "fulcra_context": { "command": "npx", "args": ["-y", "mcp-remote", "https://mcp.fulcradynamics.com/mcp"] } } }Technical Analysis
The documented
uv tool run,uvx, andnpx -ycommands can retrieve packages from external registries and execute them locally. The package references do not specify exact versions, hashes, lockfiles, or other integrity constraints. Consequently, the code executed by these commands can change after the skill package has been reviewed.This creates a supply-chain trust gap: a compromised publisher account, malicious package update, registry compromise, or dependency-resolution attack could cause arbitrary changed code to execute with the privileges of the user or agent process. The risk is elevated because these tools participate in authentication and may process highly sensitive health, biometric, calendar, location, and file data.
The audit found no evidence that the current named packages are malicious. The confirmed issue is the unsafe, unpinned retrieval and executio ...[truncated 1588 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every directly executed package to an exact, reviewed version, such as
mcp-remote@X.Y.Z, and use equivalent exact-version syntax forfulcra-apiandfulcra-context-mcp. - Use lockfiles and cryptographic hash verification where supported. Commit the lockfile or verified dependency manifest with the reviewed skill release.
- Avoid
npx -yfor security-sensitive installation paths. Require explicit user approval before first-time retrieval and execution. - Prefer preinstalled, reviewed binaries or packages from a controlled environment for workflows that can access private context or authentication state.
- Document the expected package registry and prevent fallback to untrusted indexes or registries.
- Run retrieved tools with least privilege, isolate them from unrelated credentials and files, and restrict outbound network access to required Fulcra and authentication endpoints where practical.
- Establish a dependency update process that reviews source changes and provenance before updating pinned versions.
- Re-audit package versions whenever pins are changed, rather than automatically tracking the latest release.
- Pin every directly executed package to an exact, reviewed version, such as
