T08 · Insecure Dependencies
- Location
SKILL.md:42- Finding
Automatic Execution of an Unpinned Third-Party MCP Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 42–49
Vulnerability Type: Unpinned and automatically executed third-party dependency
Risk Level: MediumVulnerable Code
json { "mcpServers": { "pipeworx-fbiwanted": { "command": "npx", "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/fbiwanted/mcp"] } } }Technical Analysis
The MCP configuration invokes
npxwith the-yoption and the mutable package specificationmcp-remote@latest. This causes npm to resolve, download, and execute whichever package release thelatesttag references at runtime, without interactive approval.Because neither an exact version nor an integrity value is specified, the code executed after installation can differ from the code that was originally reviewed. If the npm package, its maintainer account, publication process, or dependency chain is compromised, attacker-controlled code could execute with the permissions of the user running the agent.
The configuration also connects the package to
https://gateway.pipeworx.io/fbiwanted/mcp, allowing remote MCP behavior to change independently of the static skill documentation. However, the confirmed vulnerability is the unsafe dependency-execution pattern; the available evidence does not establish that the package or endpoint is currently malicious.Attack Path
- An attacker compromises the
mcp-remotenpm package, its publisher account, or a dependency included in a future release. - The attacker publishes a malicious release and causes the npm
latesttag to resolve to it. - A user or agent starts the configured
pipeworx-fbiwantedMCP server. npx -y mcp-remote@latestautomatically downloads and executes the attacker-controlled release without requesting confirmation.- The malicious package runs under the agent user's operating-system account and can attempt to access resources available ...[truncated 816 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
mcp-remote@latestwith an exact, reviewed version, such asmcp-remote@x.y.z. - Use a lockfile and integrity-verified installation workflow so package contents cannot change silently.
- Verify npm package provenance, publisher identity, release signatures, and dependency tree before deployment.
- Remove automatic
-yapproval where practical and require explicit confirmation before downloading or executing a new package. - Preinstall the reviewed dependency from a controlled registry or approved internal artifact repository rather than downloading it during MCP startup.
- Run the MCP process in a sandbox or container with minimal filesystem access, a restricted environment, no unnecessary credentials, and outbound network access limited to approved destinations.
- Monitor and pin the remote MCP tool schema so unexpected tools or behavioral changes from the external endpoint are rejected.
- Document clearly that search queries are transmitted to the third-party Pipeworx gateway rather than sent directly to an FBI-operated endpoint.
- Replace
