Back to skill

Security audit

Pipeworx fbiwanted

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent FBI Wanted search purpose, but its MCP setup automatically runs an unpinned third-party package and sends queries through a Pipeworx gateway.

Install only if you are comfortable with search queries being handled by the Pipeworx gateway and with the MCP server startup downloading and running an unpinned npm package. Prefer a pinned, reviewed mcp-remote version or a sandboxed environment with limited filesystem, environment-variable, and network access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:42
Finding

Automatic Execution of an Unpinned Third-Party MCP Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 42–49
Vulnerability Type: Unpinned and automatically executed third-party dependency
Risk Level: Medium

Vulnerable Code

json
{
  "mcpServers": {
    "pipeworx-fbiwanted": {
      "command": "npx",
      "args": ["-y", "mcp-remote@latest", "https://gateway.pipeworx.io/fbiwanted/mcp"]
    }
  }
}

Technical Analysis

The MCP configuration invokes npx with the -y option and the mutable package specification mcp-remote@latest. This causes npm to resolve, download, and execute whichever package release the latest tag references at runtime, without interactive approval.

Because neither an exact version nor an integrity value is specified, the code executed after installation can differ from the code that was originally reviewed. If the npm package, its maintainer account, publication process, or dependency chain is compromised, attacker-controlled code could execute with the permissions of the user running the agent.

The configuration also connects the package to https://gateway.pipeworx.io/fbiwanted/mcp, allowing remote MCP behavior to change independently of the static skill documentation. However, the confirmed vulnerability is the unsafe dependency-execution pattern; the available evidence does not establish that the package or endpoint is currently malicious.

Attack Path

  1. An attacker compromises the mcp-remote npm package, its publisher account, or a dependency included in a future release.
  2. The attacker publishes a malicious release and causes the npm latest tag to resolve to it.
  3. A user or agent starts the configured pipeworx-fbiwanted MCP server.
  4. npx -y mcp-remote@latest automatically downloads and executes the attacker-controlled release without requesting confirmation.
  5. The malicious package runs under the agent user's operating-system account and can attempt to access resources available ...[truncated 816 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace mcp-remote@latest with an exact, reviewed version, such as mcp-remote@x.y.z.
  2. Use a lockfile and integrity-verified installation workflow so package contents cannot change silently.
  3. Verify npm package provenance, publisher identity, release signatures, and dependency tree before deployment.
  4. Remove automatic -y approval where practical and require explicit confirmation before downloading or executing a new package.
  5. Preinstall the reviewed dependency from a controlled registry or approved internal artifact repository rather than downloading it during MCP startup.
  6. Run the MCP process in a sandbox or container with minimal filesystem access, a restricted environment, no unnecessary credentials, and outbound network access limited to approved destinations.
  7. Monitor and pin the remote MCP tool schema so unexpected tools or behavioral changes from the external endpoint are rejected.
  8. Document clearly that search queries are transmitted to the third-party Pipeworx gateway rather than sent directly to an FBI-operated endpoint.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
openclaw:
    requires:
      bins:
        - curl
    emoji: "🔎"
    homepage: https://pipeworx.io/packs/fbiwanted
---

Static analysis

No suspicious patterns detected.