T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Third-Party Package Execution via npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15–25
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code
markdown ## Connect to the MCP Server Add to Claude Desktop config (`~/Library/Application Support/Claude/claude_desktop_config.json`): ```json { "mcpServers": { "carbon-defi": { "command": "npx", "args": ["mcp-remote", "https://mcp.carbondefi.xyz/mcp"] } } }text ### Technical Analysis The documented configuration launches `mcp-remote` through `npx` without specifying an exact package version. Depending on the local npm environment, `npx` may retrieve and execute the package version currently resolved from the configured package registry. The project provides no lockfile, integrity hash, verified artifact, or package-version constraint for this command. Consequently, the code executed on a user's machine can change after the Skill has been reviewed. A compromised package publisher, npm account, registry, or newly published malicious release could turn the documented setup command into a local code-execution vector. Connecting to the remote MCP endpoint is part of the Skill's declared functionality and is not, by itself, evidence of malicious behavior. The confirmed weakness is the unsafe, unpinned dependency execution mechanism. ### Attack Path 1. An attacker compromises the `mcp-remote` package publisher, its release process, or a package registry used by the victim. 2. The attacker publishes a malicious release that remains resolvable under the unversioned package name. 3. A user follows the Skill's instructions and adds the supplied `npx mcp-remote` configuration to Claude Desktop. 4. Claude Desktop invokes `npx`, which retrieves or resolves the attacker-controlled package release. 5. The malicious package executes with the privileges of the desktop user. 6. It may access files and creden ...[truncated 755 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
mcp-remoteto an exact, reviewed version rather than resolving the latest available release. - Install the dependency through a lockfile-controlled deployment process and verify the package integrity hash.
- Document the expected package publisher, version, checksum, and trusted registry.
- Prefer a locally installed and reviewed MCP client binary over implicit runtime downloads through
npx. - Disable npm lifecycle scripts where compatible with the package and deployment process.
- Run the MCP client under a dedicated, least-privileged account or sandbox with restricted filesystem, credential, and network access.
- Require users to verify unsigned transaction destination addresses and calldata against independently published Carbon DeFi contract addresses and encoding specifications before signing.
- Establish a controlled update process in which new dependency versions are reviewed and tested before deployment.
- Pin
