T08 · Insecure Dependencies
- Location
SKILL.md:76- Finding
Unpinned Third-Party MCP Package Is Downloaded and Executed with API Credentials
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 76–90
Vulnerability Type: Unpinned runtime dependency execution
Risk Level: HighVulnerable Code
markdown Add to the user's MCP config (Cursor: `~/.cursor/mcp.json`, Claude Desktop: `claude_desktop_config.json`): ```json { "mcpServers": { "n8n": { "command": "npx", "args": ["-y", "@automatelab/n8n-mcp"], "env": { "N8N_API_URL": "https://your-n8n.example.com", "N8N_API_KEY": "n8n_..." } } } }text ### Technical Analysis The configuration invokes `npx -y @automatelab/n8n-mcp` without pinning an exact package version. The `-y` option suppresses confirmation, allowing the package manager to retrieve and execute the registry-selected package release automatically. The project provides no lockfile, integrity hash, vendored implementation, or other mechanism for ensuring that the code executed later is identical to the code reviewed during this audit. The resulting MCP process is also given `N8N_API_URL` and `N8N_API_KEY`. These values are necessary for the Skill's declared live-instance features, but they significantly increase the consequences of unsafe dependency execution. A malicious or compromised package version would execute locally under the MCP host user's account and receive the API credentials through its environment. Merely mentioning the MCP configuration paths does not establish unauthorized credential-file access. No hardcoded operational credential or covert exfiltration endpoint was identified in the supplied file. The vulnerability is the mutable, unverified dependency being executed in a credential-bearing process. ### Attack Path 1. An attacker compromises the npm package, one of its dependencies, its maintainer account, or the relevant package publication process. 2. The attacker publishes a malicious release that is selected because the configuration do ...[truncated 1263 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
@automatelab/n8n-mcpto a reviewed exact version rather than allowing registry resolution to select a mutable release. - Install the package ahead of time using a committed lockfile with integrity metadata, then configure the MCP host to invoke the reviewed local executable. Avoid downloading dependencies when the server starts.
- Verify package provenance, publisher identity, release signatures or attestations where available, and the complete transitive dependency tree before deployment.
- Remove
-yso unexpected package installation cannot occur silently, although this is not a substitute for version pinning and integrity verification. - Use a dedicated, revocable n8n API key with only the permissions required for the intended operations. Separate read-only audit access from workflow creation or activation access where n8n's access model permits it.
- Do not provide
N8N_API_KEYfor users who only require the four documented stateless tools. - Run the MCP server in a sandbox or container with restricted filesystem access, a minimal environment, and outbound network access limited to the expected n8n endpoint and required package infrastructure.
- Rotate the API key after suspected package compromise and review n8n audit logs, workflow modifications, activation events, and execution access for unauthorized activity.
- Pin
